sansec.io Critical Adobe Commerce Flaw Allows Account Takeover
Article Content
- •CVE-2026-71362 allows unauthenticated account takeover in Adobe Commerce.
- •Sansec's Shield WAF is blocking exploitation attempts of this vulnerability.
- •Adobe released patches on August 11, 2026, but active exploitation is reported.
A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento platforms has been exploited, allowing unauthenticated attackers to hijack customer accounts. The flaw, rated 9.1 on the CVSS scale, enables attackers to switch customer sessions without needing existing accounts or user interaction. Adobe released isolated patches on August 11, 2026, addressing this and six other vulnerabilities. Sansec's Shield WAF is actively blocking exploitation attempts. Website administrators are urged to apply the latest security updates to protect sensitive customer data. The vulnerability was confirmed by Sansec, which noted that it could lead to unauthorized access to private information. As of now, exploitation attempts are ongoing, although Adobe claims no known exploits were in the wild at the time of the advisory.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track CVE-2026-71362 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authorization Flaw in Adobe Commerce and Magento Exposed On August 11, 2026, Adobe released a security update addressing CVE-2026-71362, a critical Incorrect Authorization vulnerability in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. This flaw allows unauthenticated account takeover, enabling attackers to switch customer sessions without any user…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…