Adobe security advisory (AV26-808) – Update 1
At a glance
- Severity
- CriticalCVSS 9.1
- Used in attacks
- Not on CISA’s list
- Flaws named
- CVE-2026-71362
- Vendors and products
- Adobe
- Industries
- Retail & e-commerce
- Reported by
- 1 outlet
As of August 11, 2026, Adobe is affected by vulnerabilities in the following products:
- Adobe Campaign Classic
- Prior to or equal to ACC v7: 7.4.3 build 9399
- Adobe Commerce
- Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug
- Adobe Commerce B2B
- Prior to or equal to 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul and 1.3.3-2026-jul
- ColdFusion 2023
- Prior to or equal to 2023.0.22
- ColdFusion 2025
- Prior to or equal to 2025.0.11
- Content Credentials Command-Line Tool
- Prior to or equal to c2patool-v0.27.5
- Content Credentials JS SDK
- Prior to or equal to @contentauth/c2pa-web@0.12.0
- Content Credentials Rust SDK
- Prior to or equal to c2pa-v0.90.5
- Lightroom Classic
- Prior to or equal to 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1
- Magento Open Source
- Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul and 2.4.6-2026-jul
Update 1
Open-source reporting indicates that CVE-2026-71362 is being exploited in the wild.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Vulnerabilities referenced
- CVE-2026-713629.1Critical
Adobe Commerce
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
Patch or advisory available
Full record →
Coverage
One outlet has carried this so far.
2026-09-10 16:03 UTC
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News · 2026-09-16