SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilityAdobe CommerceMagento

Adobe commerce: cve-2026-71362 is now being exploited

CVE-2026-71362 joined KEV after exploitation reports involving Adobe Commerce and Magento. Stores should verify their versions and access logs.

By Soclyde Team

A merchant checks an online store after a security update

In summary

  • CVE-2026-71362 is an incorrect-authorization flaw affecting Adobe Commerce and Magento Open Source.
  • Canada’s Cyber Centre reported its September 24 KEV listing and reported exploitation.
  • Patch stores, review customer and administrator accounts and inspect administration logs.

Explore next

Soclyde resources

Article contents

On September 24, 2026, Canada’s Cyber Centre reported that CISA had added CVE-2026-71362 to KEV. Public reporting describes exploitation of an incorrect-authorization flaw in Adobe Commerce, Adobe Commerce B2B and Magento Open Source.

For a store, the risk is not limited to the storefront: accounts, orders and administration functions can contain sensitive data and access. Adobe’s bulletin remains the source of truth for exact versions and fixes.

What Adobe fixed

APSB26-92 describes an authorization vulnerability that can grant elevated access to sensitive resources without user interaction. Affected products and version levels differ between Commerce, B2B and Magento Open Source.

A vulnerable store is not automatically compromised, but it should be treated as a priority when exposed and listed in the bulletin.

The KEV signal

The Canadian advisory says CISA added the CVE to KEV on September 24 and that public reports describe exploitation. Sources do not provide a complete list of affected stores, so separate exploitation in the wild from impact on your installation.

That distinction avoids falsely reassuring a vulnerable store while avoiding an unsupported claim of customer-account takeover.

Checking the store

Inventory Commerce, B2B or Magento versions, extensions and administration exposure. Apply the relevant Adobe fix and confirm that it reached every application node.

Preserve web and administration logs. Look for new accounts, privilege changes, configuration edits, unusual orders and sign-ins from unexpected locations.

Accounts and secrets

If suspicious activity is confirmed or plausible, reset administrator accounts and rotate integration keys, payment secrets or hosting access according to scope. Review sensitive customer accounts without forcing a global reset without evidence.

Treat urgent payment or reset requests after patching carefully: a compromised store can support highly personalised phishing.

The Soclyde connection

Soclyde does not patch Adobe Commerce or verify a store’s orders and accounts. It can help organise administrative and integration access after rotation by generating unique secrets and storing them in local-first encrypted vaults.

That reduces credential copies in crisis conversations without replacing application review or payment-provider controls.

Key takeaways

CVE-2026-71362 is being exploited and affects specific Adobe Commerce and Magento versions. Check inventory, apply APSB26-92, review accounts and logs, and rotate secrets when needed. Read the secure password generator guide or contact Soclyde.

Frequently asked questions

Which platforms are affected?

Adobe cites Adobe Commerce, Adobe Commerce B2B and Magento Open Source across versions before the August 2026 fixes. Check the bulletin and the version actually deployed.

Does the flaw take over customer accounts?

Sources describe incorrect authorization that may grant elevated access to sensitive resources. Exact impact depends on version and configuration; do not generalise to every store.

What should be checked after patching?

Review administrator and customer accounts, configuration changes, unusual orders and access logs; rotate secrets when exposure is plausible.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading