Apply updates to patch critical vulnerability in Adobe Commerce and Magento Open Source

This message is intended for U-M IT staff who are responsible for systems running Adobe Commerce or Magento Open Source.

Summary

Adobe released security updates on Tuesday, August 11, to patch multiple vulnerabilities. This includes a critical vulnerability in Adobe Commerce that allows unauthenticated remote code execution and privilege escalation. Apply the updates as soon as possible after appropriate testing.

The need for immediate action supersedes the remediation timeframes in Vulnerability Management (DS-21).

Problem

Critical vulnerability (CVE-2026-71362) lets an unauthenticated remote attacker switch a customer session to another customer account and escalate privileges without requiring administrator access. Indications have emerged that threat actors are attempting to exploit the vulnerability in the wild.

CVE-2026-71362 is one of seven vulnerabilities that Adobe has addressed.

Threats

Indications have emerged that threat actors are attempting to exploit the critical vulnerability (CVE-2026-71362) in the wild.

Affected Systems

Adobe Commerce, Commerce B2B, and Magento Open Source release lines on all platforms. See the Adobe Security Bulletin for the detailed list.

Action Items

Apply the August 2026 security updates as soon as possible: Latest Product Security Updates.

Website administrators must first ensure they’re running the latest -p release available for their supported release branch before applying the corresponding isolated patch.

Technical Details

Details for each of the seven vulnerabilities:

  • CVE-2026-71362 (9.1, critical severity): Incorrect authorization vulnerability that could be leveraged to gain elevated access to sensitive resources without authentication.
  • CVE-2026-48414 (7.7, high severity): Stored cross-site scripting vulnerability that could result in arbitrary code execution. Exploitation requires authentication and administrator privileges.
  • CVE-2026-48413 (8.7, high severity): Stored cross-site scripting vulnerability that could result in arbitrary code execution. It requires authentication but not administrator privileges.
  • CVE-2026-48415 (7.6, high severity): Incorrect-authorization vulnerability affecting Adobe Commerce B2B that could enable a security-feature bypass. It requires authentication but not administrator privileges.
  • CVE-2026-48416 (7.5, high severity): Incorrect-authorization vulnerability that could enable a security-feature bypass. It requires neither authentication nor administrator privileges.
  • CVE-2026-48411 (6.5, medium severity): Incorrect-authorization vulnerability that could enable a security-feature bypass. Exploitation requires authentication and administrator privileges.
  • CVE-2026-48412 (2.7, low severity): Incorrect-authorization vulnerability that could result in privilege escalation. Exploitation requires authentication and administrator privileges.

Questions, Concerns, Reports

Please contact ITS Information Assurance through the ITS Service Center.