Adobe Commerce’s August Patch Now Comes With a Reason to Hunt for Intruders
Adobe shipped fixes for a critical Commerce and Magento privilege-escalation flaw in August. CISA has now confirmed that attackers are exploiting it. That changes the work from a normal version upgrade into two separate questions: is the correct release installed, and did anyone gain elevated access before it arrived?
The vulnerability is CVE-2026-71362, an incorrect-authorisation weakness affecting Adobe Commerce and Magento Open Source. Adobe rates it Critical with a CVSS score of 9.1. The vendor says exploitation requires no authentication, no administrative privileges and no user interaction.
CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 24 September 2026 and set a 27 September remediation deadline for covered US federal civilian agencies. The catalogue also marks forensic triage as required and ransomware use as unknown.
The evidence changed after Adobe’s bulletin
Adobe published APSB26-92 on 11 August and last updated it on 18 August. At that point, the company said it was not aware of exploits in the wild for any of the vulnerabilities in the release. CISA’s later entry is not proof that Adobe’s original statement was wrong. It records a material change in what was known by 24 September.
CISA’s public alert says the addition is based on evidence of active exploitation. Neither the alert nor the catalogue identifies an actor, victim, exploitation volume or exact request sequence. The public evidence therefore supports urgent remediation and investigation, but not claims about a specific campaign or a mass compromise of online shops.
The distinction matters because Adobe’s August bulletin contains several different vulnerabilities. Only the identity and characteristics attached to CVE-2026-71362 should be used for this incident-response decision.
No account is required to cross the authorisation boundary
Adobe classifies the issue as incorrect authorisation and says successful exploitation can produce privilege escalation. Its CVSS vector describes a network-reachable attack with low complexity, no privileges and no user interaction. Confidentiality and integrity impact are high, while availability impact is not part of the base-score consequence.
That is a different risk from a bug that begins with a compromised administrator. A vulnerable shop cannot rely on login controls alone to protect the affected boundary. A web application firewall may reduce some traffic, but the reviewed vendor bulletin does not present a WAF rule as a replacement for installing the corrected release.
Adobe has not disclosed a public endpoint, exploit payload or reliable network signature in APSB26-92. Defenders should avoid building the entire investigation around a guessed request pattern. Start with exposure, version and privilege-sensitive activity, then narrow the hunt as stronger evidence becomes available.
The fixed release must match the product branch
Adobe recommends updating to the newest version. APSB26-92 maps the affected July release lines to their corresponding August releases:
| Product | Affected versions | Corrected releases listed by Adobe |
|---|---|---|
| Adobe Commerce | 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul and 2.4.4-2026-jul, plus earlier releases in those lines | The matching 2.4.9, 2.4.8, 2.4.7, 2.4.6, 2.4.5 and 2.4.4 -2026-aug releases |
| Adobe Commerce B2B | 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul and 1.3.3-2026-jul, plus earlier releases in those lines | The matching 1.5.3, 1.5.2, 1.4.2, 1.3.4 and 1.3.3 -2026-aug releases |
| Magento Open Source | 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul and 2.4.6-2026-jul, plus earlier releases in those lines | The matching 2.4.9, 2.4.8, 2.4.7 and 2.4.6 -2026-aug releases |
A successful deployment job is not enough evidence. Verify the package version on every production node, including systems removed from a load balancer, disaster-recovery copies, staging environments with production data and instances managed by a separate commerce team. An overlooked node can preserve both the exposure and the evidence.
Investigate the exposed period before cleaning it away
BlackTree recommends preserving web, application, administrator, identity-provider and infrastructure logs covering the period before the August fix was installed. Review unexplained access to privileged functions or sensitive resources, changes to administrator accounts and roles, new integrations, unusual exports and activity by service identities outside their normal pattern.
Do not erase a suspicious system merely to reach a clean version number. Capture the evidence needed to understand what the application and any elevated session could reach. If unauthorised privilege use cannot be excluded, review and rotate exposed credentials, API tokens and integration secrets from a trusted environment.
CISA’s 27 September deadline applies to covered US federal civilian agencies, not as a universal legal deadline for every organisation. Its wider relevance is operational: the catalogue confirms exploitation. The required federal forensic-triage step is a reminder to keep patching and investigation separate.
This is not the StyleSmuggler vulnerability
BlackTree previously covered StyleSmuggler, a separate Magento and Adobe Commerce attack path involving template handling. Product overlap does not make the two issues interchangeable.
The vulnerability in this article is the incorrect-authorisation flaw in APSB26-92. Its patch instructions must come from that bulletin. The separate StyleSmuggler hotfix and credential-rotation guidance are not replacements for verifying the August release that fixes this flaw.
The practical test is simple but demanding. Confirm the correct release on every relevant node, preserve evidence from the exposed window and investigate privilege-sensitive activity. A shop that is patched today may still need to answer what happened yesterday.
Sources
- Adobe security bulletin APSB26-92, published 11 August 2026 and last updated 18 August 2026. Adobe provides no publication or update time.
- CISA, Adds Two Known Exploited Vulnerabilities to Catalog, released 24 September 2026. CISA provides no publication time.
- CISA official KEV repository feed, checked 29 September 2026. The entry records addition on 24 September, a 27 September due date, forensic triage set to yes and ransomware use as unknown.


