ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security
Part of a story covered by 5 sources: “N-able N-central pre-auth RCE (CVE-2026-86218) exploited in the wild and added to CISA KEV; Akamai details StyleSmuggler, Canada flags another Adobe Commerce flaw” — merged summary and timeline →

Adobe security advisory (AV26-808) – Update 1

highAdvisory exploited in the wildimportance 55CVE-2026-71362
AI summary · glm-5.3-flash

Canada's Cyber Centre updated Adobe advisory AV26-808 to flag that CVE-2026-71362 in Adobe Commerce is being exploited in the wild.

The Canadian Centre for Cyber Security advisory AV26-808 (Update 1) lists vulnerabilities affecting Adobe products including Campaign Classic, Adobe Commerce, Magento Open Source, ColdFusion 2023/2025, Lightroom Classic, and Content Credentials SDKs. Update 1 notes that open-source reporting indicates CVE-2026-71362 is being exploited in the wild. Users and administrators are urged to review the referenced links and apply updates, including those in Adobe bulletin APSB26-92 for Adobe Commerce.

  • CVE-2026-71362 is being exploited in the wild, per open-source reporting
  • Affected products include Adobe Commerce, Magento Open Source, ColdFusion, Lightroom Classic, and Campaign Classic
  • Commerce updates are tracked under Adobe security bulletin APSB26-92
  • Canadian Cyber Centre urges administrators to apply the available patches

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-71362
Unauthenticated Privilege Escalation Flaw in Adobe Commerce (Magento)

CVE-2026-71362 is an incorrect-authorization flaw (CWE-863) in Adobe Commerce, the e-commerce platform formerly known as Magento, in which authorization checks are applied incorrectly and can be bypassed. It is triggered over the network without authentication or user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). A successful attacker gains elevated access to sensitive resources — a privilege-escalation condition that Adobe's APSB26-92 advisory and press coverage describe as an account-takeover risk. Any organization running an unpatched Adobe Commerce/Magento deployment is affected; exact version ranges are listed in Adobe security bulletin APSB26-92. The flaw came under active attack shortly after public disclosure, and its EPSS score of 25.1% (98th percentile) signals a high likelihood of continued near-term exploitation.

Do: Apply the fix released under Adobe advisory APSB26-92 immediately, prioritizing internet-facing Commerce/Magento instances, and check the bulletin for the exact patched version ranges for your deployment. Because exploitation requires no credentials or user interaction, review admin accounts, API integrations, and user/role assignments for unauthorized privilege changes, and restrict admin-panel and storefront API access where feasible. Monitor Adobe's advisory for indicators of compromise given confirmed in-the-wild exploitation.

9.125%
  • Adobe Commerce (Magento)
mass≈200,000+ Magento/Adobe Commerce storefronts worldwide
Full article187 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-808
Date: August 12, 2026
Updated: September 10, 2026

As of August 11, 2026, Adobe is affected by vulnerabilities in the following products:

  • Adobe Campaign Classic
    • Prior to or equal to ACC v7: 7.4.3 build 9399
  • Adobe Commerce
    • Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug
  • Adobe Commerce B2B
    • Prior to or equal to 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul and 1.3.3-2026-jul
  • ColdFusion 2023
    • Prior to or equal to 2023.0.22
  • ColdFusion 2025
    • Prior to or equal to 2025.0.11
  • Content Credentials Command-Line Tool
    • Prior to or equal to c2patool-v0.27.5
  • Content Credentials JS SDK
  • Content Credentials Rust SDK
    • Prior to or equal to c2pa-v0.90.5
  • Lightroom Classic
    • Prior to or equal to 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1
  • Magento Open Source
    • Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul and 2.4.6-2026-jul

Update 1

Open-source reporting indicates that CVE-2026-71362 is being exploited in the wild.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-808