Active Exploitation Alert: Adobe Commerce / Magento Incorrect Authorization Account Takeover — CVE-2026-71362 Added to CISA KEV

Active Exploitation Alert: Adobe Commerce / Magento Incorrect Authorization Account Takeover — CVE-2026-71362 Added to CISA KEV

Executive Summary

CVE-2026-71362 is a critical Incorrect Authorization flaw (CWE-863) in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Adobe rates CVSS 3.1 9.1 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)—privilege escalation and elevated access to sensitive resources with no user interaction and no privileges required. Third-party researchers (Sansec and others) characterize the impact as unauthenticated customer account takeover: switching a customer session to another customer account, yielding access to the victim account and private customer data.

Fixed in Adobe Security Bulletin APSB26-92 (published August 11, 2026) via August 2026 isolated security patches / -2026-aug release levels. Affected framing is approximately -2026-jul and earlier for the listed product lines.

CISA added CVE-2026-71362 to the Known Exploited Vulnerabilities catalog on September 24, 2026 (due date September 27, 2026 for FCEB under BOD 26-04; known ransomware campaign use = Unknown; forensic triage = Yes). The same CISA alert also added WSO2 CVE-2026-5430. Exploitation signals include Sansec-reported blocked attempts around August 2026 and a Previdian honeypot attempt on September 10, 2026 (Australia IP; address not published). As of September 25, 2026 reporting, Adobe had not yet updated the advisory to confirm exploitation status.

Separation note: This advisory is not StyleSmuggler CVE-2026-75650 (CWE-1336 template-engine RCE, APSB26-146, KEV added 2026-09-08 / due 2026-09-11, CVSS 10.0)—a separate Magento/Commerce KEV already covered elsewhere. Different CVE, bug class, bulletin, CVSS, and KEV dates.

Primary APSB26-92 helpx HTML was Access Denied (403) / timed out from research egress on 2026-09-29; version and CVSS facts below prefer NVD Adobe CNA fields, Adobe Experience League KA-40380, and reputable secondaries—cited transparently.

Technical Information

CVE-2026-71362 is Incorrect Authorization (CWE-863). Per NVD / Adobe CNA: the flaw can allow privilege escalation and elevated access to sensitive resources without user interaction (UI:N, PR:N).

Sansec patch review (2026-08-11): Magento customer identity / account session handling; an attacker can switch a customer session to another customer account → access to the victim account and private customer data; no existing account, admin privileges, or user interaction required.

APSB26-92 also addresses additional CVEs (XSS / other authorization issues)—out of scope for this single-CVE advisory except as bulletin context.

Primary sources reviewed do not publish MITRE ATT&CK technique ID mappings for this CVE. This advisory does not invent ATT&CK IDs or actor attribution. Informal behavior (unauthenticated session/identity abuse leading to account takeover) is descriptive only.

Affected Product Versions

Vendor: Adobe. Products: Adobe Commerce (on-premises / Cloud), Adobe Commerce B2B, Magento Open Source.

Fixed / unaffected (August 2026 — treat -2026-aug as fixed)

Adobe Commerce: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug.

Adobe Commerce B2B: 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug.

Magento Open Source: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug.

Affected (approximately -2026-jul and earlier)

Adobe Commerce: 2.4.9-2026-jul, 2.4.8-2026-jul (and earlier in line), 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul and earlier for those lines (NVD CPE also enumerates many pN builds through 2.4.9).

Adobe Commerce B2B: 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul and earlier in those lines.

Magento Open Source: 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul and earlier.

Adobe Experience League KA-40380 (Isolated patch baselines)

Affected framing (Cloud / on-prem / Open Source): 2.4.9; 2.4.8-p5 and earlier; 2.4.7-p10 and earlier; 2.4.6-p15 and earlier; 2.4.5-p17 and earlier; 2.4.4-p18 and earlier. August 2026 isolated ZIPs are keyed to those baselines. Merchants must be on the latest security-only -p for the line and apply prior monthly isolated patches cumulatively before the August patch.

Data-quality note: NVD Adobe CNA "affected" strings oddly include some *-2026-aug tokens in lessThanOrEqual blobs; Writer guidance treats -2026-aug as the fixed set and -2026-jul and earlier as affected, consistent with Meetanshi APSB26-92 summary and KA-40380.

Workaround and Mitigation

  1. Primary remediation: Apply APSB26-92 August 2026 fixes—either the matching -2026-aug release for the product line or Adobe Isolated patch ZIPs after prerequisites (latest -p baseline + prior monthly isolated patches cumulative) per KA-40380 / Sansec / NVD references.
  2. Verify with Commerce Version Tool (php vendor/bin/patch-status) where available (KA-40380).
  3. No official Adobe workaround short of patching was identified in retrieved official sources for this PR:N authorization issue.
  4. Compensating controls (secondary / TPRM guidance only—not Adobe-sourced): review storefront and admin internet exposure; consider vendor shield / WAF claims carefully (e.g. Sansec Shield pre-patch block is vendor marketing); monitor for customer-session anomalies. Do not invent WAF signatures.
  5. CISA KEV requiredAction: apply vendor mitigations; comply with BOD 26-04 and Forensics Triage Requirements; for cloud services follow BOD 26-04 cloud guidance or discontinue use if mitigations unavailable; evaluate internet exposure.

Dual-track note (without merging bug narratives): confirm APSB26-92 for this ATO issue separately from any prior StyleSmuggler APSB26-146 remediation if both apply to the estate.

Indicators of Compromise

None published with actionable values (IPs, URLs, hashes, UA strings) in retrieved primary or secondary sources. Honest empty for classic IoCs.

  • Previdian (via The Hacker News): a lone Australia IP attempted exploit against honeypots on 2026-09-10—specific address not published; not usable as an IoC without the octet string.
  • Malware / PoC hashes: none retrieved from primary sources; do not chase PoC binaries.

Do not invent ATT&CK technique IDs or additional IoCs beyond what sources publish.

References

Third-Party Risk Bridge: Magento / Adobe Commerce Storefronts in the Supply Chain

Adobe Commerce and Magento Open Source (including B2B and Cloud) are common ecommerce storefront platforms in merchant and MSP supply chains—material third-party and in-house ecommerce dependencies, not a niche CMS footnote. CVE-2026-71362 is incorrect authorization enabling unauthenticated elevated access that third parties describe as customer session switch → account takeover (CVSS 9.1), fixed in APSB26-92, and listed in CISA KEV from September 24, 2026 (due September 27, 2026) amid active exploitation evidence. Ask every merchant or MSP: Exact Commerce / Magento / B2B version and whether -2026-aug or August isolated patches (APSB26-92) are applied? Were storefront/admin (and relevant APIs) internet-exposed between disclosure (~2026-08-11) and patch? Any customer-account or session anomalies? Confirm APSB26-92 separately from any StyleSmuggler APSB26-146 work—do not merge the two bug narratives.

Book a demo to see how Rescana tracks ecommerce-platform vendors for KEV exposure, patch-level attestation, and forensic-triage evidence.

Forward this advisory to your TPRM owner if a supplier or MSP operates Adobe Commerce or Magento storefronts for your estate—they own the APSB26-92 / -2026-aug attestation, exposure-window, and customer-session anomaly asks above.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.