PULSE
FEED
ransomstorm reclama a First Secure Bank Group · US · Financial Servicesransomqilin reclama a XICO · MX · Not Foundransomqilin reclama a Island · CA · Technologyransomqilin reclama a Revenga Smart Solutions · ES · Technologyransomqilin reclama a Willatt & Flickinger · US · Not Foundransomarcusmedia reclama a Pantaneiro Capas · BR · Manufacturingransomemperador reclama a Car Service Abschlepp · DE · Transportationransomm3rx reclama a cipher.systems · US · Technologyransombarracuda reclama a International Chemical Co. · Manufacturingransompayoutsking reclama a M****n · US · Not Foundransomstorm reclama a Applied Composites · US · Manufacturingransomstorm reclama a Magna Legal Services · US · Professional Servicesransomthegentlemen reclama a Ligue se Grupo · PT · Otherransomthegentlemen reclama a Charles Keith · SG · Retail & E-Commerceransomstorm reclama a First Secure Bank Group · US · Financial Servicesransomqilin reclama a XICO · MX · Not Foundransomqilin reclama a Island · CA · Technologyransomqilin reclama a Revenga Smart Solutions · ES · Technologyransomqilin reclama a Willatt & Flickinger · US · Not Foundransomarcusmedia reclama a Pantaneiro Capas · BR · Manufacturingransomemperador reclama a Car Service Abschlepp · DE · Transportationransomm3rx reclama a cipher.systems · US · Technologyransombarracuda reclama a International Chemical Co. · Manufacturingransompayoutsking reclama a M****n · US · Not Foundransomstorm reclama a Applied Composites · US · Manufacturingransomstorm reclama a Magna Legal Services · US · Professional Servicesransomthegentlemen reclama a Ligue se Grupo · PT · Otherransomthegentlemen reclama a Charles Keith · SG · Retail & E-Commerce
← Todos los CVEs
CVE Watch25 sept 2026

CVE-2026-71362

Adobe Commerce and Magento Incorrect Authorization Vulnerability

CVSS

9.1

Crítico

EPSS

87.5%

p100

KEV

SÍ

24 sept 2026

Exploit Today

80

0-100

Publicado: 11 ago 2026 · Última mod.: 25 sept 2026 · CWE-863

EPSS · 30d
2.3%EPSS · 30 días89.6%
2026-08-302026-09-26
Ficha del catálogo KEV

Producto

Adobe / Commerce and Magento

Vulnerabilidad

Adobe Commerce and Magento Incorrect Authorization Vulnerability

Añadido a KEV

24 sept 2026

Remediar antes de

27 sept 2026

Uso conocido en ransomware

No

Descripción resumida

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

Acción requerida

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Notas

https://helpx.adobe.com/security/products/magento/apsb26-92.html ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-71362

Descripción técnica

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1010565.3 MED
—
———Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads.6h
CVE-2026-1010485.4 MED
—
———Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) without requiring the Admin.Write OAuth scope, unlike the node create/update/delete routes. An OAuth client that has been authorized by an administrator with only the Admin.Read scope can therefore submit attacker-controlled node definitions and cause the Cloudreve server to issue outbound requests to arbitrary URLs, enabling blind server-side request forgery, internal service probing, and delivery of signed Cloudreve slave-style requests to attacker-chosen endpoints.6h
CVE-2026-1008695.9 MED
—
———Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that payment gateways execute while Sylius maintains order as paid, causing financial loss.11h
CVE-2026-1007447.3 ALT
—
———A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 4.2.0 is sufficient to fix this issue. This patch is called 39ae16de4248075de8c08f3259114e064b20d52d. It is advisable to upgrade the affected component.22h
CVE-2026-1007219.0 CRÍ
—
———vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-string boundary. Untrusted guest code can therefore require the allowlisted module (e.g. `foo`) and then require the absolute path of a non-allowlisted sibling whose path merely shares the resolved prefix (e.g. `.../node_modules/foo2/index.js`); the sibling passes `isPathAllowedForModule` and is loaded through `hostRequire`, so its top-level code runs in the host process before the exports are wrapped with `vm.readonly`, resulting in a sandbox escape and arbitrary code execution in the host context.22h
CVE-2026-1007047.7 ALT
—
——0Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1) evaluator never reads the spec.images and spec.allowedValues fields of a PolicyException. Any PolicyException whose policyRefs and matchConditions match a resource causes image signature verification to be skipped for the entire resource rather than only for the listed images or values, so an exception intended to exempt a single trusted image exempts every image on the matched resource(s). As a result, unsigned or untrusted images can be admitted to the cluster without signature verification. This differs from ValidatingPolicy, GeneratingPolicy, and MutatingPolicy, which treat the same field as a partial exemption. The issue is fixed in version 1.19.1.1d