HIGHVulnerability
Verified
Global
CISA KEV: Adobe Commerce and Magento — Adobe Commerce and Magento Incorrect Authorization Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
Analysis
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-24. Remediation due: 2026-09-27.