Critical Adobe Commerce Flaw Enables Customer Account Takeover

Critical Adobe Commerce Flaw Enables Customer Account Takeover

First seen 12 Aug 2026, 21:50 UTC Bleepingcomputerwiz.iosansec.io 86% similarity 72.0

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento platforms allows attackers to hijack customer accounts without authentication. The flaw, rated 9.1 on the CVSS scale, enables exploitation without existing accounts or user interaction. Adobe released a security update (APSB26-92) on August 11, 2026, addressing this and six other vulnerabilities. Sansec's Shield WAF is actively blocking exploitation attempts. Website administrators are advised to apply the August 2026 security update immediately to mitigate risks. The vulnerability stems from improper handling of customer identity in account sessions, allowing attackers to switch sessions between accounts. Adobe's advisory states they are not aware of any exploits in the wild, but the potential for significant data breaches exists.

Key Points: • CVE-2026-71362 allows account takeover without authentication or user interaction. • Adobe released a patch on August 11, 2026, addressing this and six other vulnerabilities. • Sansec Shield is actively blocking exploitation attempts of this critical flaw.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
CVE-2026-71362 published
Adobe disclosed a critical vulnerability allowing unauthenticated account takeover in Commerce and Magento.
BleepingComputer
2026-08-11
Adobe releases APSB26-92 patch
Adobe issued isolated patch files for seven vulnerabilities, including CVE-2026-71362.
sansec.io
2026-08-12
Exploitation attempts detected
Sansec reports that its Shield WAF is blocking attempts to exploit CVE-2026-71362.
BleepingComputer

Community

Browse all →