CVE-2026-71362CISA KEVEPSS p99.8%
CVE-2026-71362Adobe Commerce and Magento Incorrect Authorization Vulnerability
Adobe / Commerce and Magento
Description
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
Scoring
| CVSS | 9.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 87.51% probability of exploitation · percentile 99.8% · 2026-10-01T12:00:22Z |
| Last modified | 2026-09-25 |
CISA KEV entry
Added to KEV: 2026-09-24