On September 24, 2026, Canada’s Cyber Centre reported that CISA had added CVE-2026-71362 to KEV. Public reporting describes exploitation of an incorrect-authorization flaw in Adobe Commerce, Adobe Commerce B2B and Magento Open Source.
For a store, the risk is not limited to the storefront: accounts, orders and administration functions can contain sensitive data and access. Adobe’s bulletin remains the source of truth for exact versions and fixes.
What Adobe fixed
APSB26-92 describes an authorization vulnerability that can grant elevated access to sensitive resources without user interaction. Affected products and version levels differ between Commerce, B2B and Magento Open Source.
A vulnerable store is not automatically compromised, but it should be treated as a priority when exposed and listed in the bulletin.
The KEV signal
The Canadian advisory says CISA added the CVE to KEV on September 24 and that public reports describe exploitation. Sources do not provide a complete list of affected stores, so separate exploitation in the wild from impact on your installation.
That distinction avoids falsely reassuring a vulnerable store while avoiding an unsupported claim of customer-account takeover.
Checking the store
Inventory Commerce, B2B or Magento versions, extensions and administration exposure. Apply the relevant Adobe fix and confirm that it reached every application node.
Preserve web and administration logs. Look for new accounts, privilege changes, configuration edits, unusual orders and sign-ins from unexpected locations.
Accounts and secrets
If suspicious activity is confirmed or plausible, reset administrator accounts and rotate integration keys, payment secrets or hosting access according to scope. Review sensitive customer accounts without forcing a global reset without evidence.
Treat urgent payment or reset requests after patching carefully: a compromised store can support highly personalised phishing.
The Soclyde connection
Soclyde does not patch Adobe Commerce or verify a store’s orders and accounts. It can help organise administrative and integration access after rotation by generating unique secrets and storing them in local-first encrypted vaults.
That reduces credential copies in crisis conversations without replacing application review or payment-provider controls.
Key takeaways
CVE-2026-71362 is being exploited and affects specific Adobe Commerce and Magento versions. Check inventory, apply APSB26-92, review accounts and logs, and rotate secrets when needed. Read the secure password generator guide or contact Soclyde.



