CVE-2026-71362 explained: the Adobe Commerce flaw and how to fix it

Introduction
CVE-2026-71362 is a security flaw in Adobe Commerce, the platform many online stores run on. It lets an attacker gain elevated access to your store without logging in and without tricking anyone into clicking anything. If your business runs Adobe Commerce, Commerce B2B, or Magento, keep reading.
Does this affect you?
The two-minute check
- Log in to your online store's admin panel and look for the platform name.
- Check the footer or the system information page for "Adobe Commerce," "Commerce B2B," or "Magento."
- If you're not sure, ask whoever built or maintains your store which platform it runs on.
When you can stop reading
If your website does not run Adobe Commerce, Commerce B2B, or Magento, this flaw does not apply to you. You can close this tab.
How bad is it, honestly?
What the official record says
The National Vulnerability Database (NVD) rates this flaw 9.1 out of 10, listed as CRITICAL (NVD). The scoring details say an attacker can reach this flaw over the network. They don't need a password or account on your system. They don't need you to click a link or open a file.
The Exploit Prediction Scoring System (EPSS) puts the probability of exploitation at 90%, in the 99.78th percentile of all known vulnerabilities (EPSS). EPSS is a forecast of exploitation activity, not a measure of how severe the flaw itself is.
This flaw is also on the CISA Known Exploited Vulnerabilities (KEV) catalog. That means it isn't theoretical, criminals are already using it (CISA).
What that means for a business like yours
The record describes this as a privilege escalation flaw. That means an attacker who finds a small opening can grant themselves higher access, the kind normally reserved for your store administrators. Elevated access like that could let someone read or change sensitive data in your store, such as customer records or order details. The record does not say this flaw can be used to take your store offline, only to gain unauthorized access to it.
If your store handles customer payment or personal data, this is worth pairing with a look at your FTC Safeguards Rule obligations.
What to do about it, step by step
If someone else manages your IT
Copy and send this to your IT provider or web developer. Send it as three separate lines, not one long request.
- "Please check whether our store runs Adobe Commerce, Commerce B2B, or Magento."
- "This is related to CVE-2026-71362, which is on the CISA Known Exploited Vulnerabilities catalog."
- "Please confirm the fix from Adobe's advisory has been applied and reply when it's done."
If you manage it yourself
- Log in to your Adobe Commerce admin panel using an administrator account.
- Open the vendor advisory for this flaw.
- Follow the steps in the advisory to apply the fix for your setup.
- Clear your store's cache after the fix is applied, if the advisory says to.
- Confirm the fix using the check in the next section.
How long you have
This flaw is already on the CISA Known Exploited Vulnerabilities (KEV) catalog, added on 2026-09-24 (CISA). Federal agencies were given until 2026-09-27 to fix it. That short window reflects how seriously the government treats a flaw that's already being used in attacks. Your business isn't bound by the federal deadline, but the same urgency applies here. As noted above, the EPSS score points to a high chance of exploitation. Treat this as something to fix today, not something to schedule for later.
How to check it actually worked
- Open the vendor advisory and note the fix details for your setup.
- Check your store's system information page for the applied fix or patch level.
- Compare what you see against what the advisory describes as fixed.
- Ask your IT provider or developer for written confirmation that the fix is in place.
Don't rely on a progress bar or an "update complete" message alone. Confirm the actual version or patch level matches what the advisory names.
What to do if you can't patch right now
If you can't apply the fix immediately, a few interim steps reduce your exposure. None of them replace the fix.
- Restrict access to your admin panel to known office locations or a virtual private network (VPN). This limits who can even reach the login screen, but doesn't remove the flaw.
- Require multi-factor authentication (MFA) on every admin account. This makes stolen passwords less useful, but this flaw doesn't require a password at all.
- Review admin account activity logs for anything unusual. This helps you catch an attack in progress, but it isn't prevention.
A managed cybersecurity service can help monitor for this kind of activity while you plan the fix. Tightening who can reach administrative systems is also part of good privileged access management.
Frequently Asked Questions
Do I have to do anything if we only use this at home?
Adobe Commerce, Commerce B2B, and Magento run online stores, not home computers. If you don't operate a store on one of these platforms, this flaw doesn't apply to you.
Will applying the fix break anything?
The record doesn't say. Vendor fixes can occasionally change behavior, so it's reasonable to test on a staging copy of your store first if you have one, or ask your developer to do so.
How do I know if we've already been attacked?
The record doesn't say how to detect past exploitation. Reviewing admin account activity logs for unfamiliar logins or unexpected changes is a reasonable starting point.
What if our developer says it's already fine?
Ask for the specific version or patch level and confirm it matches what the vendor advisory describes as fixed. A verbal "it's fine" isn't the same as a confirmed patch level.
Does this affect other software we use?
The record only names Adobe Commerce, Commerce B2B, and Magento. It doesn't say anything about other software your business runs.
If you're not sure where your store stands, or you'd rather have someone confirm it for you, LayerLogix offers a free IT assessment and can help from there. Our team brings 20+ years of experience and 100% Texas-based support to businesses across The Woodlands, Round Rock, Greater Houston, DFW, and Austin. Contact us if you want a hand with this one.
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.


