Product of Adobe

Commerce and Magento

As of , 3 Adobe Commerce and Magento vulnerabilities are on CISA's list of exploited vulnerabilities; 2 were added in 2026. Patch first: CVE-2026-71362.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-71362Incorrect AuthorizationAdobe Commerce and MagentoPatch nowForensic triage required by CISA; listed in the last 14 days0.88
2CVE-2026-75650Improper Neutralization of Special Elements Used in a Template EngineAdobe Commerce and MagentoPatch nowForensic triage required by CISA0.04
3CVE-2025-54236Improper Input ValidationAdobe Commerce and MagentoPatch this weekMetasploit module; EPSS 0.950.95

Added each year

0.511.522025: 1120252026: 222026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20251
20262

Used in ransomware