Threat Overview
CVE-2026-71362 is a critical incorrect-authorization vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Adobe rates it CVSS 9.1 and states exploitation requires neither authentication nor administrative privileges and can result in privilege escalation. Adobe’s August 11 bulletin initially reported no known exploitation. CISA added CVE-2026-71362 to the Known Exploited Vulnerabilities catalog on September 24, 2026, establishing subsequent exploitation in the wild.
References
- Adobe Security Bulletin APSB26-92, August 11, 2026, updated August 18: https://helpx.adobe.com/security/products/magento/apsb26-92.html
- CISA Known Exploited Vulnerabilities Catalog, CVE-2026-71362 added September 24, 2026: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- The Hacker News, September 25, 2026: https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html
Impacted Systems
Adobe Commerce, Adobe Commerce B2B, and Magento Open Source releases listed as affected in APSB26-92. Adobe lists the applicable August 2026 security releases as fixed. Internet-facing storefront and API exposure materially increases risk. Customers should use the Adobe bulletin to match the exact fixed release to their deployed branch.
Why this matters
Commerce platforms process customer data, administrative sessions, payment-related workflows, API integrations, and business-critical transactions. An unauthenticated privilege-escalation flaw with confirmed exploitation can provide elevated access without an initial user compromise.
Exploitation Status
Confirmed exploitation based on CISA KEV inclusion on September 24. No specific actor or ransomware association was reliably confirmed in the sources reviewed.
What this hunt looks for
Anomalous access to Commerce/Magento applications, rare web sources, web-server or PHP child shells, unexpected PHP/script creation, persistence, and new outbound destinations from application hosts.
Required logs
Microsoft Defender endpoint telemetry from application hosts, web/WAF or firewall telemetry in CommonSecurityLog, and Linux Syslog where available.
First Pass – Web Server or PHP Spawning Shells
DeviceProcessEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName in~ ("php","php-fpm","apache2","httpd","nginx")
| where FileName in~ ("sh","bash","dash","cmd.exe","powershell.exe","pwsh.exe","python","python3","curl","wget")
| project Timestamp,DeviceName,AccountName,InitiatingProcessFileName,InitiatingProcessCommandLine,FileName,ProcessCommandLine,SHA256
| order by Timestamp desc
PHP Files Created by Web Processes
DeviceFileEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName in~ ("php","php-fpm","apache2","httpd","nginx")
| where ActionType in~ ("FileCreated","FileModified")
| where FileName endswith ".php" or FileName endswith ".phtml"
| project Timestamp,DeviceName,ActionType,FileName,FolderPath,SHA256,InitiatingProcessFileName,InitiatingProcessCommandLine
| order by Timestamp desc
Web Process Outbound Connections
DeviceNetworkEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName in~ ("php","php-fpm","apache2","httpd","nginx")
| project Timestamp,DeviceName,InitiatingProcessFileName,InitiatingProcessCommandLine,RemoteUrl,RemoteIP,RemotePort
| order by Timestamp desc
New Web Process Destinations
let Baseline=DeviceNetworkEvents
| where Timestamp between (ago(30d)..ago(7d))
| where InitiatingProcessFileName in~ ("php","php-fpm","apache2","httpd","nginx")
| summarize by DeviceId,RemoteIP,RemoteUrl;
DeviceNetworkEvents
| where Timestamp >= ago(7d)
| where InitiatingProcessFileName in~ ("php","php-fpm","apache2","httpd","nginx")
| join kind=leftanti Baseline on DeviceId,RemoteIP,RemoteUrl
| project Timestamp,DeviceName,InitiatingProcessFileName,InitiatingProcessCommandLine,RemoteUrl,RemoteIP,RemotePort
| order by Timestamp desc
Rare Sources to Commerce Web Servers
let Baseline=CommonSecurityLog
| where TimeGenerated between (ago(30d)..ago(7d))
| summarize by DestinationIP,SourceIP;
CommonSecurityLog
| where TimeGenerated >= ago(7d)
| join kind=leftanti Baseline on DestinationIP,SourceIP
| project TimeGenerated,SourceIP,DestinationIP,DestinationPort,RequestMethod,RequestURL,DeviceAction,Message
| order by TimeGenerated desc
High-Volume Requests from a Single Source
CommonSecurityLog
| where TimeGenerated >= ago(7d)
| summarize Requests=count(),Destinations=dcount(DestinationIP),URLs=dcount(RequestURL) by SourceIP,bin(TimeGenerated,5m)
| where Requests >= 100
| order by Requests desc
Web Process Persistence Activity
DeviceProcessEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName in~ ("php","php-fpm","apache2","httpd","nginx","sh","bash")
| where FileName in~ ("systemctl","crontab","at","schtasks.exe","sc.exe")
| project Timestamp,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName,InitiatingProcessCommandLine
| order by Timestamp desc
Linux Web Application Syslog Fallback
Syslog
| where TimeGenerated >= ago(30d)
| where ProcessName has_any ("php","apache","httpd","nginx") or SyslogMessage has_any ("Magento","Adobe Commerce")
| where SyslogMessage has_any ("ERROR","FATAL","Exception","sudo","curl ","wget ","bash","sh -c")
| project TimeGenerated,Computer,HostName,ProcessName,SeverityLevel,SyslogMessage
| order by TimeGenerated desc
Detection Notes
No reliable public exploit request signature was available in the authoritative sources reviewed, so generic traversal, endpoint names, or payload strings were intentionally not invented. The first-pass endpoint query is high signal when the Commerce host is onboarded to Defender. CommonSecurityLog queries should be scoped to known Commerce/Magento destination IPs or hostnames. PHP file creation can be legitimate during deployment, cache generation, extension changes, or upgrades.