CISA added CVE-2026-71362 (Adobe Commerce and Magento ) to its Known Exploited Vulnerabilities catalog on September 24, 2026, which means there is reliable evidence of exploitation in the wild. Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
Why it matters
CISA lists this as exploited in the wild. Unpatched Commerce and Magento systems are exposed to active attacks now.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.
CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing…
Why it matters
CISA lists this as exploited in the wild. Unpatched BIG-IP and Multiple Products systems are exposed to active attacks now.