• News/
  • bleepingcomputer-20260812205459

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

BleepingComputer
·
Bill Toulas
·
Published Aug 12, 2026
·
Updated

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. The flaw is described as an incorrect authorization vulnerability that could be leveraged to "gain elevated access to sensitive resources" without authentication and is one of the seven issues that Adobe addressed in a security update yesterday. Although the software vendor states in the advisory that it is not aware of exploits in the wild for any of the fixed flaws, eCommerce security company Sansec says that its Shield web application firewall (WAF) is already blocking CVE-2026-71362 exploitation attempts. According to Sansec, exploiting the vulnerability requires "no existing account, administrator privileges or user interaction." After analyzing Adobe’s patch, the researchers pinned the problem to Magento improperly handling customer identity in an account session. "Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim's account and private customer data," the security company explains. Four of the other flaws Adobe fixed with yesterday's updates received a high-severity score, and the other two are medium and low severity: Website administrators are advised to apply the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release...

Read full article

Affected Software

2 affected components
Adobe Commerce
Adobe Magento
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in Adobe Commerce and Magento platforms that is being exploited to hijack customer accounts.

2

What security implications are discussed in this article?

The article highlights the risk of customer account hijacking due to an incorrect authorization vulnerability in Adobe's e-commerce platforms.

3

What specific vulnerability is mentioned in the article?

The vulnerability mentioned is identified as CVE-2026-71362.

4

What products or software are affected by this vulnerability?

The affected products include Adobe Commerce, Adobe Commerce B2B, and Adobe Magento.

5

When was this vulnerability first detected and reported?

The vulnerability was detected and reported on August 12, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203