Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe’s Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.

The flaw is described as an incorrect authorization vulnerability that could be leveraged to “gain elevated access to sensitive resources” without authentication and is one of the seven issues that Adobe addressed in a security update yesterday.

Although the software vendor states in the advisory that it is not aware of exploits in the wild for any of the fixed flaws, eCommerce security company Sansec says that its Shield web application firewall (WAF) is already blocking CVE-2026-71362 exploitation attempts.

According to Sansec, exploiting the vulnerability requires “no existing account, administrator privileges or user interaction.”

After analyzing Adobe’s patch, the researchers pinned the problem to Magento improperly handling customer identity in an account session.

“Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data,” the security company explains.

Four of the other flaws Adobe fixed with yesterday’s updates received a high-severity score, and the other two are medium and low severity:

Website administrators are advised to apply the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible.

According to Sansec, these monthly fixes are distributed as isolated patch files rather than a new security release or updated Composer packages.

Website admins must first ensure they’re running the latest -p release available for their supported release branch before applying the corresponding isolated patch.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Max severity Adobe ColdFusion flaw now exploited in attacks

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

Sonicwall warns of new SMA1000 zero-day exploited in attacks

Critical Progress LoadMaster flaw now actively exploited in attacks

N-able warns of N-central auth bypass flaw exploited in attacks

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

LexisNexis shuts down services after suspicious activity on servers

Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.

See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats

Overdue a password health-check? Audit your Active Directory for free

Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.

Overdue a password health-check? Audit your Active Directory for free

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.