the August authorisation flaw
CVE-2026-71362 APSB26-92 Adobe Commerce / Magento 2.x CISA KEV 2026-09-24
If it is missing Adobe's APSB26-92 update, an incorrect-authorisation flaw lets an unauthenticated attacker escalate privileges and reach resources they should not — CVSS 9.1, no login and no user interaction. Adobe Commerce up to 2.4.4, Magento Open Source up to 2.4.6 and Adobe Commerce B2B up to 1.3.3 are named in the advisory. Adobe published the fix on 11 August 2026, exploitation attempts began within days, and CISA added it to the Known Exploited Vulnerabilities catalogue on 24 September — verify the exact patch level.
Is my store affected?
A free passive scan tells you whether your store is on an affected line, along with everything else we can see from outside. It takes under a minute and needs no account.
How we detect this
We infer the platform and version line from signals the storefront serves publicly — the version endpoint when it is reachable, markup and cookie markers when it is not, and the fingerprints of static assets that changed between releases. If that line is one CVE-2026-71362 affects, we say so.
We do not attempt to exploit it, and we never claim a store is vulnerable from a version string alone. A patched store and an unpatched one on the same release look identical from outside, so the finding is marked inferred and phrased as something to verify. It does not affect your grade.
How to fix it
Apply Adobe's APSB26-92 update — the August 2026 security release for your line, or the isolated patch if you cannot take the full release yet.
-
1
See what the Quality Patches Tool offers for your exact version. If the tool is not installed: composer require magento/quality-patches
vendor/bin/magento-patches status
-
2
Take the August 2026 security release for your line, which is the route Adobe documents. Use your edition's metapackage and the exact version from the advisory.
composer require magento/product-<your-edition>-edition:<2026-aug-release> --no-update && composer update --with-dependencies
-
3
If you cannot take the full release yet, Adobe ships an isolated patch for this bulletin that closes it without a version upgrade. Apply that instead, and schedule the release.
vendor/bin/magento-patches apply APSB26-92
-
4
Rebuild so the patched code is compiled and served. This publishes the change the previous step made; skip static-content:deploy in developer mode.
bin/magento setup:upgrade && bin/magento setup:di:compile && bin/magento setup:static-content:deploy -f && bin/magento cache:flush
-
5
This one escalates privileges rather than running code, so the thing to check afterwards is accounts: admin users you do not recognise, and integration tokens nobody remembers creating.
SELECT user_id, username, email, created, logdate FROM admin_user ORDER BY user_id DESC; SELECT name, status, created_at FROM oauth_token ORDER BY entity_id DESC LIMIT 50;
vendor/bin/magento-patches -n status | grep -i -e APSB26-92 -e 71362
References
From intelligence vault 2026.09.6, released 2026-09-25. What changed