sansec.io
Critical Adobe Commerce Flaw Allows Account Takeover
Article Content
A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento platforms has been exploited, allowing unauthenticated attackers to hijack customer accounts. The flaw, rated 9.1 on the CVSS scale, enables attackers to switch customer sessions without needing existing accounts or user interaction. Adobe released isolated patches on August 11, 2026, addressing this and six other vulnerabilities. Sansec's Shield WAF is actively blocking exploitation attempts. Website administrators are urged to apply the latest security updates to protect sensitive customer data. The vulnerability was confirmed by Sansec, which noted that it could lead to unauthorized access to private information. As of now, exploitation attempts are ongoing, although Adobe claims no known exploits were in the wild at the time of the advisory.
Key Points: • CVE-2026-71362 allows unauthenticated account takeover in Adobe Commerce. • Sansec's Shield WAF is blocking exploitation attempts of this vulnerability. • Adobe released patches on August 11, 2026, but active exploitation is reported.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.