CVE-2026-71362 carries a CVSS 3.1 base score of 9.1 against Adobe Commerce, Adobe’s enterprise e-commerce platform built on the Magento codebase. NVD classifies it as CWE-863 (Incorrect Authorization). VulnCheck’s KEV feed reports the CVE as exploited, dated September 3, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-71362 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s own summary states this plainly: an incorrect authorization vulnerability that could result in privilege escalation, letting an attacker gain elevated access to sensitive resources. NVD confirms exploitation of this issue does not require user interaction, consistent with the CVSS vector’s UI:N value and PR:N (no privileges required) for the attacker’s own starting position. NVD’s record does not name the specific authorization check that fails or which sensitive resources become reachable; Adobe’s own security bulletin, cited directly from NVD’s reference list, is the authoritative technical source, but our source data does not carry deeper mechanism detail beyond what’s summarized here.
We report NVD’s classification as stated rather than speculating about the missing mechanism detail.
Evidence and confidence
- Medium confidence — the CVSS 9.1 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), and the CWE-863 classification all trace to NVD alone, which cites Adobe’s own security bulletin as the authoritative technical source. The exploitation report traces to VulnCheck KEV alone. - Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.2452, a 97.8th percentile score as of our ingestion — one of the highest scores in our recent coverage.
No field is in conflict between our two sources. Our data carries no fixed-version field; consult Adobe’s own security bulletin directly for version-specific remediation guidance.
Why this matters
Adobe Commerce runs enterprise-scale online stores, and a privilege-escalation flaw reachable without user interaction or prior privileges is a serious threat to any merchant running an affected installation — the CVSS impact profile (C:H/I:H) indicates both confidentiality and integrity are fully compromised once exploited, covering customer data, order records, and store configuration. The near-maximal EPSS percentile independently corroborates the urgency the VulnCheck exploitation report and CVSS score already suggest.
Because our source data doesn’t carry Adobe’s own mechanism-level detail or a specific fixed-version figure, merchants running Adobe Commerce should treat Adobe’s own security bulletin as the primary source for both understanding scope and identifying the correct patched release, rather than relying on this summary alone for remediation steps.
Frequently Asked Questions
What is CVE-2026-71362? A CVSS 9.1 incorrect authorization vulnerability (CWE-863) in Adobe Commerce, allowing privilege escalation to sensitive resources without requiring user interaction.
Is CVE-2026-71362 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 3, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration. FIRST’s EPSS model independently scores this CVE at the 97.8th percentile, corroborating high exploitation likelihood through a different signal.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Our data carries no fixed-version field. Consult Adobe’s own security bulletin directly for version-specific patching guidance.
Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-71362, which cites Adobe’s own security bulletin APSB26-92 as the authoritative technical source. Exploitation status and the September 3, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.