Defensive self-check · CISA KEV 2026-09-24

Adobe Commerce and Magento CVE-2026-71362 self-check

CISA added CVE-2026-71362 on 2026-09-24. It is an incorrect-authorization issue in Adobe Commerce and Magento. Confirm the version on a store you operate. No exploit steps are included.

Check these three things

  • Version. In the admin footer, or in composer.lock, read the magento/product-community-edition or Commerce version and compare it with Adobe's fixed release.
  • Admin roles. Open System → Permissions → All Users and review accounts created or changed since 2026-09-24.
  • Integrations. Open System → Extensions → Integrations and revoke tokens your store does not use.

What to do

Apply the Adobe security update, flush cache, and repeat the user and integration review. Treat unexpected administrator accounts as a reason to rotate admin passwords and integration tokens.

Vendor record: CISA KEV catalog, entry CVE-2026-71362.