Skip to content

security_identifier

CVE-2026-71362

Incorrect authorization vulnerability in Adobe Commerce and Magento Open Source that allows an unauthenticated attacker to take over customer sessions, scored CVSS 9.1.

Current clusters

security4 publishers

Exploited WSO2 and Magento flaws draw a September 27 federal patch deadline

CISA set a September 27, 2026 federal deadline for exploited flaws in WSO2 and Adobe Commerce. According to The Hacker News, the WSO2 bug leads to code execution on API gateways, and the Magento bug lets an attacker take over customer sessions without logging in.

Perspective Coverage

4 publishers
Builder
Builder 28%
Operator
Operator 65%
Investor
Investor 7%

Reality

Evidence76
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence70