CVE-2026-71362CISA KEVEPSS p99.8%

CVE-2026-71362Adobe Commerce and Magento Incorrect Authorization Vulnerability

Adobe / Commerce and Magento

Description

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

Scoring

CVSS 9.1 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS87.51% probability of exploitation · percentile 99.8% · 2026-10-01T12:00:22Z
Last modified2026-09-25

CISA KEV entry

Added to KEV: 2026-09-24

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.