Adobe security advisory (AV26-808) – Update 1

CriticalCVSS 9.1Canadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
CriticalCVSS 9.1
Used in attacks
Not on CISA’s list
Flaws named
CVE-2026-71362
Vendors and products
Adobe
Reported by
1 outlet

As of August 11, 2026, Adobe is affected by vulnerabilities in the following products:

  • Adobe Campaign Classic
    • Prior to or equal to ACC v7: 7.4.3 build 9399
  • Adobe Commerce
    • Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug
  • Adobe Commerce B2B
    • Prior to or equal to 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul and 1.3.3-2026-jul
  • ColdFusion 2023
    • Prior to or equal to 2023.0.22
  • ColdFusion 2025
    • Prior to or equal to 2025.0.11
  • Content Credentials Command-Line Tool
    • Prior to or equal to c2patool-v0.27.5
  • Content Credentials JS SDK
    • Prior to or equal to @contentauth/c2pa-web@0.12.0
  • Content Credentials Rust SDK
    • Prior to or equal to c2pa-v0.90.5
  • Lightroom Classic
    • Prior to or equal to 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1
  • Magento Open Source
    • Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul and 2.4.6-2026-jul

Update 1

Open-source reporting indicates that CVE-2026-71362 is being exploited in the wild.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Vulnerabilities referenced

  • CVE-2026-713629.1Critical

    Adobe Commerce

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

    Patch or advisory available

    Full record →

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber SecurityOfficial SourceFirst reported

    2026-09-10 16:03 UTC

Related stories