Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-71362
CVE
CVE-2026-71362
View on NVD ↗
Adobe Commerce | Incorrect Authorization (CWE-863)
Source Articles
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. CVE-2026-5430 is a path traversal flaw in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway that enables unrestricted file upload and remote code execution. CVE-2026-71362 is an incorrect authorization vulnerability in Adobe Commerce and Magento that allows attackers to escalate privileges and access sensitive customer data without user interaction. Exploitation of both vulnerabilities has been observed in the wild, with attacks detected as early as September 10, 2026.
hacker-news
Sep 25, 2026