CVE-2026-71362Critical· 9.1▾ Hadal⚠ Exploited in the wildPoC availableAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue do…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 50.1 · likelihood 17.9 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
25%
Federal remediation due Sep 27, 2026
Last analysed / modified upstream
25% → 90%
1 GitHub repo · Nuclei ×1 (last check)
Added to the CISA catalog on Sep 24, 2026. Federal remediation due Sep 27, 2026. View catalog ↗
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
commerce < 2.4.4commerce = 2.4.4commerce = 2.4.5commerce = 2.4.6commerce = 2.4.7commerce = 2.4.8commerce = 2.4.9commerce_b2b < 1.3.3commerce_b2b = 1.3.3commerce_b2b = 1.3.4commerce_b2b = 1.4.2commerce_b2b = 1.5.2commerce_b2b = 1.5.3magento <= 2.4.6magento = 2.4.7magento = 2.4.8magento = 2.4.9Upgrade past the affected range:
commerce 2.4.4commerce_b2b 1.3.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48415High· 7.6Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass
CVE-2026-48412Low· 2.7Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation
CVE-2026-48411Medium· 6.5Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass
CVE-2026-75650Critical· 10.0Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-77108High· 7.5Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation
CVE-2026-77111High· 8.7Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass