Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5022 articles · 188920 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-71362PATCHED
adobe · adobe commerce

Adobe Commerce | Incorrect Authorization (CWE-863)

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Affected Products

VendorProductVersions
adobeadobe commerce0, 0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
adobemagentocert_advisory90%

References

  • https://helpx.adobe.com/security/products/magento/apsb26-92.html(vendor-advisory)

Related News (4 articles)

Tier B
BSI Advisories8h ago
[NEU] [hoch] Adobe Magento: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security9h ago
Patchday Adobe: Schadcode-Schlupflöcher bedrohen Campaign Classic und ColdFusion
→ No new info (linked only)
Tier C
VulDB22h ago
CVE-2026-71362 | Adobe Commerce/Commerce B2B/Magento Open Source improper authorization
→ No new info (linked only)
Tier D
SecurityWeek1d ago
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2.4.9-2026-aug2.4.8-2026-aug2.4.7-2026-aug2.4.6-2026-aug2.4.5-2026-aug2.4.4-2026-aug1.5.3-2026-aug1.5.2-2026-aug1.4.2-2026-aug1.3.4-2026-aug1.3.3-2026-aug2.4.9-2026-aug2.4.8-2026-aug2.4.7-2026-aug2.4.6-2026-aug
CWECWE-863
PublishedAug 11, 2026
Last enriched22h ago
Trending Score62
Source articles4
Independent4
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-48362
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Trending: 63
HIGHCVE-2026-48386
ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)
Trending: 47
HIGHCVE-2026-21279
ColdFusion | Improper Input Validation (CWE-20)
Trending: 47
HIGHCVE-2026-48414
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Trending: 46
HIGHCVE-2026-48441
Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Trending: 46

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Patch Available
Aug 12, 2026