sansec.io
Critical Adobe Commerce Flaw Enables Customer Account Takeover
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento platforms allows attackers to hijack customer accounts without authentication. The flaw, rated 9.1 on the CVSS scale, enables exploitation without existing accounts or user interaction. Adobe released a security update (APSB26-92) on August 11, 2026, addressing this and six other vulnerabilities. Sansec's Shield WAF is actively blocking exploitation attempts. Website administrators are advised to apply the August 2026 security update immediately to mitigate risks. The vulnerability stems from improper handling of customer identity in account sessions, allowing attackers to switch sessions between accounts. Adobe's advisory states they are not aware of any exploits in the wild, but the potential for significant data breaches exists.
Key Points: • CVE-2026-71362 allows account takeover without authentication or user interaction. • Adobe released a patch on August 11, 2026, addressing this and six other vulnerabilities. • Sansec Shield is actively blocking exploitation attempts of this critical flaw.