Attackers are trying to break into online stores running Adobe Commerce and Magento by abusing a critical flaw that can let them take over customer accounts and access private account data. The bug, CVE-2026-71362, is an incorrect-authorization issue fixed in Adobe’s August 2026 updates for Adobe Commerce, Commerce B2B, and Magento release lines; Sansec says exploitation requires no account, no administrator rights, and no user interaction, and involves switching a live customer session to another customer account.
Why it matters: This puts online store operators and their customers at immediate risk of account takeover and exposure of personal shopping data. Organizations running affected Adobe Commerce or Magento versions should verify they are on the latest supported -p release and apply the August 2026 isolated patch files immediately.
Ionut Arghire
2026.08.13
96% relevant
This article directly updates the same event by adding that Sansec observed and blocked exploitation attempts shortly after Adobe disclosed and patched CVE-2026-71362, and that the bug allows unauthenticated session switching into other customers’ accounts on affected Commerce, Commerce B2B, and Magento Open Source versions through the July 2026 patch level.
Bill Toulas
2026.08.12
100% relevant
This article establishes a distinct new story by identifying active exploitation attempts for CVE-2026-71362, a different Adobe Commerce and Magento flaw than the previously tracked Adobe Commerce/Magento RCE story involving CVE-2026-45247.
← Back to all stories