Adobe Commerce / Magento CVE-2026-71362 (CVSS 9.1): unauth customer session takeover — CISA KEV 24 Sep
CISA added CVE-2026-71362 to the Known Exploited Vulnerabilities catalog on 24 September 2026 (FCEB due 27 Sep) as an incorrect-authorization flaw in Adobe Commerce and Magento Open Source that can elevate access to sensitive resources without user interaction. Sansec (11 August 2026) reviewed Adobe APSB26-92 isolated patches and confirmed the bug lets an unauthenticated attacker switch a customer session to another customer account (account takeover / private customer data). APSB26-92 is a multi-CVE isolated-patch package (seven flaws; five Critical including this CVSS 9.1 item) — not a full Composer security release; merchants must be on the latest -p line for their release before applying the isolated patch. Previdian sensors observed exploitation attempts from an Australia-geolocated IP against honeypots on 10 September 2026 (honeypot telemetry, not a named AU victim). Adobe had not updated APSB26-92 to state “exploited in the wild” as of the 25 Sep THN write-up. Affected (Previdian/vendor framing): Adobe Commerce through 2.4.9-2026-jul / 2.4.8–2.4.4-2026-aug lines; Magento Open Source through corresponding -jul lines; Adobe Commerce B2B through listed -jul lines — patched in the matching 2026-aug isolated/security levels per APSB26-92. Distinct from desk StyleSmuggler CVE-2026-75650 (APSB26-146). Primary: CISA 24 Sep KEV alert; vendor: Adobe APSB26-92; research: Sansec.
- Product
- Adobe Commerce; Magento Open Source; Adobe Commerce B2B
- Versions
- Affected until APSB26-92 isolated patches on supported 2.4.x / B2B lines (see Adobe advisory for exact -jul/-aug builds). Sansec Shield blocks exploitation pre-patch.
- CVSS
- 9.1
- Exploited in Australia?
- unknown
- Patch to
- Apply Adobe APSB26-92 isolated patches after confirming the latest -p baseline for your release line; scan stores for session-ATO abuse; Sansec Shield customers already blocked. FCEB: remediate by 27 Sep 2026 per CISA KEV/BOD 26-04.
Primary: CISA — Adds Two Known Exploited Vulnerabilities to Catalog (24 Sep 2026) · Vendor: Adobe APSB26-92 (Magento / Adobe Commerce isolated patches) · CVE: CVE-2026-71362, CVE-2026-75650 · Sansec — Adobe patches critical Magento account takeover APSB26-92 (11 Aug 2026)
