CISA KEV Alert 24 Sept 2026, 20:01 UTC

CISA Flags Actively Exploited Critical Flaw in Adobe Commerce

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2026-71362 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Adobe Commerce and Magento and is an incorrect authorisation flaw that can allow attackers to access sensitive resources with elevated privileges without user interaction.

The flaw results from inadequate authorisation controls. An attacker may exploit it to gain elevated access to sensitive resources, although the available data does not specify the attack vector or required access conditions. NVD rates the vulnerability 9.1 (Critical) under CVSS. Patch availability is currently unknown.

CISA’s KEV listing confirms active exploitation. Use in ransomware campaigns is unknown. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 27 September 2026.

CISA requires organisations to apply mitigations in accordance with Adobe’s instructions, while complying with BOD 26-04, “Prioritizing Security Updates Based on Risk”, and CISA’s “Forensics Triage Requirements”. Organisations must follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset’s internet exposure and follow BOD 26-04 patching guidance. FCEB agencies are directly affected, but all organisations should review their exposure.

See the NVD entry and CISA KEV catalogue for full details: https://nvd.nist.gov/vuln/detail/CVE-2026-71362 and https://www.cisa.gov/known-exploited-vulnerabilities-catalog.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline