Critical Adobe Commerce Flaw Allows Account Takeover

Critical Adobe Commerce Flaw Allows Account Takeover

First seen 12 Aug 2026, 21:50 UTC Securityaffairs.CoBleepingcomputersansec.ioCcb.Belgium.Bewww.wiz.io 72.6

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento platforms has been exploited, allowing unauthenticated attackers to hijack customer accounts. The flaw, rated 9.1 on the CVSS scale, enables attackers to switch customer sessions without needing existing accounts or user interaction. Adobe released isolated patches on August 11, 2026, addressing this and six other vulnerabilities. Sansec's Shield WAF is actively blocking exploitation attempts. Website administrators are urged to apply the latest security updates to protect sensitive customer data. The vulnerability was confirmed by Sansec, which noted that it could lead to unauthorized access to private information. As of now, exploitation attempts are ongoing, although Adobe claims no known exploits were in the wild at the time of the advisory.

Key Points: • CVE-2026-71362 allows unauthenticated account takeover in Adobe Commerce. • Sansec's Shield WAF is blocking exploitation attempts of this vulnerability. • Adobe released patches on August 11, 2026, but active exploitation is reported.

Timeline

2026-08-11
CVE-2026-71362 published
Adobe disclosed a critical vulnerability allowing unauthenticated account takeover in Commerce and Magento.
Bleepingcomputer
2026-08-11
Adobe releases isolated patches
Adobe released patches for seven vulnerabilities, including CVE-2026-71362, to fix critical flaws in its platforms.
sansec.io
2026-08-12
Exploitation attempts detected
Sansec reported that its Shield WAF is blocking attempts to exploit CVE-2026-71362, indicating active targeting by attackers.
Bleepingcomputer
2026-08-13
Ongoing exploitation reported
Reports confirm that hackers are actively targeting the critical Adobe Commerce flaw shortly after its public disclosure.
Securityaffairs.Co