Vulnerability threat dossier

CVE-2026-71362

adobecommerce

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

VTP deterministic threat62.4of 100 · CVSS excluded

VTP analyst assessment

Adobe Commerce authorization privilege escalation

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityCRITICAL
AI confidence86%
Public exploitation · VTP factKEV

Assessment

CISA KEV lists this Adobe Commerce and Magento authorization flaw as exploited. The issue can elevate access to sensitive resources without user interaction.

Why it matters

  • A compromised Commerce application could expose sensitive resources and affect customer-facing commerce operations.

Evidence

3 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The reporting establishes exploitation but does not describe the attack chain or affected customer population.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use affected Adobe Commerce or Magento releases, apply Adobe remediation urgently.

AI baseline history (6)
  1. BASELINE ASSESSED
    Adobe Commerce authorization privilege escalationgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Adobe Commerce authorization flaw targeted after disclosuregpt-5.6-terra · low
  3. BASELINE ASSESSED
    Adobe Commerce incorrect authorizationgpt-5.6-terra · low
  4. BASELINE ASSESSED
    Adobe Commerce authorization flawgpt-5.6-terra · low
  5. BASELINE ASSESSED
    Reported exploitation attempts against Adobe Commerce flawgpt-5.6-sol · high
  6. BASELINE ASSESSED
    Reported exploitation attempts against Adobe Commerce flawgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.1 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.90100th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.90; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EPSS MATERIAL INCREASEEPSS changed materially from 0.02 to 0.90
EPSS MATERIAL DECREASEEPSS changed materially from 0.25 to 0.02
KEV ADDEDCISA KEV entry added
EPSS MATERIAL INCREASEEPSS changed materially from 0.01 to 0.25
CERT ADVISORYNew CERT advisory
03

Claim provenance

Evidence and source independence

8publications detected
8underlying evidence chains

1 primary sources · 0 dependent secondary reports · 7 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:4fe33645b6700b35050f04660d4e40a1e4359d011382f270db0035c3eee78adbACTIVE
Evidence
04

Event history

Threat timeline

  1. 17:4525 Sept
    EPSS MATERIAL INCREASE

    EPSS changed materially from 0.02 to 0.90

    Predictive context changed; this is not exploitation evidence.

  2. 17:2425 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  3. 18:3624 Sept
    EPSS MATERIAL DECREASE

    EPSS changed materially from 0.25 to 0.02

    Predictive context changed; this is not exploitation evidence.

  4. 00:0024 Sept
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

  5. 00:3425 Aug
    EPSS MATERIAL INCREASE

    EPSS changed materially from 0.01 to 0.25

    Predictive context changed; this is not exploitation evidence.

  6. 13:0824 Aug
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-71362.

  7. 00:0013 Aug
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-71362.

05

Original publications

Source record

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...]

CVE-2026-5430CVE-2026-65660CVE-2026-67279CVE-2026-71362
Separate evidence group
Original

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in  WSO2 API Control Plane,

CVE-2026-5430CVE-2026-71362
Separate evidence group
Original

Nuclei Templates v10.4.8 - Release Notes

New Templates Added: 112 | CVEs Added: 101 | First-time contributions: 22 🔥 Release Highlights 🔥 [CVE-2026-72898] Metabase - Unauthenticated SQL Injection (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-71362 ] Adobe Commerce/Magento - Customer Session Identity Switch (@0x_Akoko, @dinosn ) [critical] 🔥 [ CVE-2026-64849 ] MLflow Webhook SSRF - Unauth Full-Read via Redirect Bypass ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [CVE-2026-64638] WordPress Core < 7.0.3 - Preauth Reflected XSS (XSS2Shell) ( @flx | Nick Vidovic (greenhats)) [high] 🔥 [ CVE-2026-63077 ] JetBrains TeamCity < 2026.1.3, 2025.11.7 - RCE (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [CVE-2026-59774] Gitea 1.22.1-1.27.0 - Unauthenticated Arbitrary File Read ( @ashish-cybersec ) [critical] 🔥 [ CVE-2026-58644 ] Microsoft SharePoint Server - WS-Federation Deserialization RCE ( @pdteam ) [critical] (kev) (vKEV) 🔥 [CVE-2026-57219] RabbitMQ Management - OAuth 2 Client Secret Disclosure ( @Aryu-RU ) [high] 🔥 [ CVE-2026-56270 ] Flowise <= 3.0.13 - Unauth OAuth Configuration Disclosure (@0x_Akoko, @pdteam ) [high] (vKEV) 🔥 [CVE-2026-53576] Kestra <= 1.3.20 - Remote Code Execution (@0x_Akoko, @pdteam , @Aryu-RU ) [critical] (vKEV) 🔥 [ CVE-2026-52806 ] Gogs <= 0.14.2 - Auth RCE via git rebase Argument Injection ( @dhiyaneshdk , @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-49049 ] JoomShaper Helix3 <=3.1.0 - Unauth Arbitrary JSON File Write ( @dhiyaneshdk , @pdteam ) [high] (vKEV) 🔥 [ CVE-2026-48939 ] Joomla iCagenda < 3.9.10 - Unauth Arbitrary File Upload RCE (@0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-40217 ] LiteLLM < 1.25.0 - Remote Code Execution ( @ritikchaddha ) [high] (vKEV) 🔥 [ CVE-2026-34908 ] UniFi OS - Authentication Bypass via Path Traversal (..%2f) ( @Boreas37 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-20896 ] Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Auth Bypass ( @prithvee07 ) [critical] (vKEV) 🔥 [ CVE-2026-19478 ] GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method Invocation (@0x_Akoko, @dhiyaneshdk ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Corrected an unclosed string literal in the CVE-2026-0558 dsl matcher (PR #16950 ). Fixed a broken matcher in the newly added CVE-2026-3395 template (PR #16886 ). Fixed the username key structure in mysql-empty-password.yaml (PR #16939 ). Fixed indentation in kubernetes-metrics.yaml (PR #16934 ). Added the missing capture group to regex extractors in oracle-containers-panel, smtp-credentials-exposure and springboot-x-application-context (PR #16663 ). Corrected the max-request counter for CVE-2021-40822 (PR #16875 ). Corrected email and password variable names in CVE-2025-68613 (PR #16918 ). Renamed Wix-detect.yaml, cve-2026-44338 .yaml and CVE-2026-44381.yaml to match the naming convention (PRs #16731 , #16729 , #16730 ). Moved 22 invalid or rejected CVE templates to vulnerabilities (PR #16889 , Issue #16115 ). Removed CVE-2024-28752 .yaml (PR #16745 ). False Negatives CVE-2017-5521 , CVE-2017-7615 and CVE-2020-23575 — regexes were placed in word matchers, so these templates could never fire (PR #16666 ). nh-c2 — corrected a dsl matcher that could never match (PR #16739 ). CVE-2026-21858 — added a /rest/sentry.js fallback to detect n8n 1.65.0 through 1.111.x (PR #16888 ). CVE-2025-14847 — now detects vulnerable MongoDB 8.0.x via buildinfo read-size truncation (PR #16741 ). CVE-2025-32969 — removed an incorrect content_type matcher that suppressed matches (PR #16704 ). CVE-2023-37629 — closed the filename quote before the .php extension so the payload is well formed (PR #16709 ). False Positives CVE-2025-29927 — added negative matchers so WAF block pages returning HTTP 200 no longer match (PR #16870 , Issue #16782 ). wp-vr-view-xss and vrview-xss — no longer fire on hosts that escape the payload (PR #16912 ). wordpress-eol — tightened an over-broad version regex (PR #16752 ). CVE-2021-24139 — both conditions must now match rather than either (PR #16748 ). Marked prec

CVE-2015-7501CVE-2017-5521CVE-2017-7615CVE-2019-1003030CVE-2020-10204CVE-2020-23575CVE-2021-24139CVE-2021-40822CVE-2022-1281CVE-2022-29013CVE-2023-25826CVE-2023-37629CVE-2024-0200CVE-2024-13985CVE-2024-28752CVE-2024-37014CVE-2024-55890CVE-2024-56064CVE-2024-57726CVE-2025-0520CVE-2025-11953CVE-2025-13342CVE-2025-13528CVE-2025-14847CVE-2025-20282CVE-2025-26399CVE-2025-29927CVE-2025-32969CVE-2025-68613CVE-2025-71324CVE-2026-0558CVE-2026-0717CVE-2026-10768CVE-2026-1115CVE-2026-11387CVE-2026-12394CVE-2026-13001CVE-2026-13147CVE-2026-14483CVE-2026-14894CVE-2026-15733CVE-2026-15826CVE-2026-16268CVE-2026-17505CVE-2026-17532CVE-2026-17594CVE-2026-19478CVE-2026-19598CVE-2026-19900CVE-2026-20896CVE-2026-21858CVE-2026-25231CVE-2026-25895CVE-2026-2614CVE-2026-26217CVE-2026-27542CVE-2026-27796CVE-2026-3001CVE-2026-30965CVE-2026-32255CVE-2026-3395CVE-2026-34908CVE-2026-34976CVE-2026-35037CVE-2026-3576CVE-2026-40217CVE-2026-40280CVE-2026-4060CVE-2026-41042CVE-2026-41432CVE-2026-42461CVE-2026-44338CVE-2026-44381CVE-2026-45332CVE-2026-45695CVE-2026-48030CVE-2026-48939CVE-2026-49049CVE-2026-49069CVE-2026-50160CVE-2026-5032CVE-2026-52806CVE-2026-53519CVE-2026-53576CVE-2026-53629CVE-2026-53753CVE-2026-53755CVE-2026-53976CVE-2026-54917CVE-2026-55087CVE-2026-55224CVE-2026-56265CVE-2026-56270CVE-2026-57219CVE-2026-57827CVE-2026-58138CVE-2026-58644CVE-2026-59774CVE-2026-61511CVE-2026-61808CVE-2026-63030CVE-2026-63077CVE-2026-64638CVE-2026-64849CVE-2026-65442CVE-2026-65919CVE-2026-67208CVE-2026-6826CVE-2026-6854CVE-2026-69084CVE-2026-69251CVE-2026-71209CVE-2026-71362CVE-2026-72898CVE-2026-8236CVE-2026-8237CVE-2026-8857CVE-2026-9506
Separate evidence group
Original

Adobe Commerce Bug Targeted Immediately After Disclosure

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek .

CVE-2026-71362
Separate evidence group
Original

Multiples vulnérabilités dans les produits Adobe (13 août 2026)

De multiples vulnérabilités ont été découvertes dans les produits Adobe. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

CVE-2026-21273CVE-2026-21279CVE-2026-25652CVE-2026-34635CVE-2026-48273CVE-2026-48362CVE-2026-48375CVE-2026-48376CVE-2026-48384CVE-2026-48386CVE-2026-48411CVE-2026-48412CVE-2026-48413CVE-2026-48414CVE-2026-48415CVE-2026-48416CVE-2026-48440CVE-2026-71362CVE-2026-71383CVE-2026-71384CVE-2026-71385CVE-2026-71386CVE-2026-71387
Separate evidence group
Original

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]

CVE-2026-48411CVE-2026-48412CVE-2026-48413CVE-2026-48414CVE-2026-48415CVE-2026-48416CVE-2026-71362
Separate evidence group
Original

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could

CVE-2026-27302CVE-2026-48273CVE-2026-48362CVE-2026-48381CVE-2026-48449CVE-2026-71362CVE-2026-71384CVE-2026-71398
Separate evidence group
Original

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

The security defects could be exploited for arbitrary code execution and denial-of-service. The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek .

CVE-2026-27302CVE-2026-48273CVE-2026-48362CVE-2026-48381CVE-2026-71362CVE-2026-71384CVE-2026-71398
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score62.4vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction17.92 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency10 / 10
Threat acceleration2 / 10
CVSS technical severityExcluded
CVSS
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE
CWE-863
CPE records
157
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.