Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4500 articles · 223826 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-71362KEVEXPLOITEDPATCHED
adobe · commerce

Adobe Commerce | Incorrect Authorization (CWE-863)

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Affected Products

VendorProductVersions
adobecommerce0, 0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
adobemagentocert_advisory90%
adobecommerce_b2bcve_cpe95%

References

  • https://helpx.adobe.com/security/products/magento/apsb26-92.html(vendor-advisory)
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-71362.yaml(exploit, nuclei)

Related News (8 articles)

Tier D
BleepingComputer2d ago
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
→ No new info (linked only)
Tier D
SecurityWeek45d ago
Adobe Commerce Bug Targeted Immediately After Disclosure
→ No new info (linked only)
Tier B
CERT-FR46d ago
Multiples vulnérabilités dans les produits Adobe (13 août 2026)
→ No new info (linked only)
Tier D
BleepingComputer46d ago
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
→ No new info (linked only)
Tier B
BSI Advisories46d ago
[NEU] [hoch] Adobe Magento: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security46d ago
Patchday Adobe: Schadcode-Schlupflöcher bedrohen Campaign Classic und ColdFusion
→ No new info (linked only)
Tier C
VulDB47d ago
CVE-2026-71362 | Adobe Commerce/Commerce B2B/Magento Open Source improper authorization
→ No new info (linked only)
Tier D
SecurityWeek47d ago
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
2.4.9-2026-aug2.4.8-2026-aug2.4.7-2026-aug2.4.6-2026-aug2.4.5-2026-aug2.4.4-2026-aug1.5.3-2026-aug1.5.2-2026-aug1.4.2-2026-aug1.3.4-2026-aug1.3.3-2026-aug2.4.9-2026-aug2.4.8-2026-aug2.4.7-2026-aug2.4.6-2026-aug
CWECWE-863
PublishedAug 11, 2026
Last enriched47d ago
Trending Score112🔥
Source articles8
Independent6
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-75745
Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863)
Trending: 36
CRITICALCVE-2026-75682
Adobe Connect | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Trending: 30
CRITICALCVE-2026-82000
Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)
Trending: 30
CRITICALCVE-2026-75698
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Trending: 30
HIGHCVE-2026-34689
Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Trending: 28

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Added to CISA KEV
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Actively Exploited
Sep 25, 2026
Exploit Available
Sep 25, 2026
Patch Available
Sep 25, 2026