ZeroHour
Security Affairspublished ()ingested @securityaffairs

Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure

criticalExploit / PoC exploited in the wildimportance 74CVE-2026-71362
AI summary · glm-5.3-flash

Attackers began exploiting critical Adobe Commerce flaw CVE-2026-71362 (CVSS 9.1) for unauthenticated customer account takeover shortly after patch release.

Sansec blocked the first exploitation attempts of CVE-2026-71362 immediately after Adobe published its advisory. The flaw lets unauthenticated attackers switch a customer session to another customer account, hijacking accounts and accessing private data without credentials, admin privileges or user interaction. It affects Adobe Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches, and Adobe issued isolated patch files APSB26-92 fixing seven vulnerabilities, including stored cross-site scripting and authorization issues.

  • No existing account, privileges or user interaction needed
  • Affects Commerce, Commerce B2B, Magento Open Source
  • Patch APSB26-92 fixes seven vulnerabilities total
  • Sansec reviewed the patch and confirmed session-switch flaw

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-71362
Unauthenticated Privilege Escalation Flaw in Adobe Commerce (Magento)

CVE-2026-71362 is an incorrect-authorization flaw (CWE-863) in Adobe Commerce, the e-commerce platform formerly known as Magento, in which authorization checks are applied incorrectly and can be bypassed. It is triggered over the network without authentication or user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). A successful attacker gains elevated access to sensitive resources — a privilege-escalation condition that Adobe's APSB26-92 advisory and press coverage describe as an account-takeover risk. Any organization running an unpatched Adobe Commerce/Magento deployment is affected; exact version ranges are listed in Adobe security bulletin APSB26-92. The flaw came under active attack shortly after public disclosure, and its EPSS score of 25.1% (98th percentile) signals a high likelihood of continued near-term exploitation.

Do: Apply the fix released under Adobe advisory APSB26-92 immediately, prioritizing internet-facing Commerce/Magento instances, and check the bulletin for the exact patched version ranges for your deployment. Because exploitation requires no credentials or user interaction, review admin accounts, API integrations, and user/role assignments for unauthorized privilege changes, and restrict admin-panel and storefront API access where feasible. Monitor Adobe's advisory for indicators of compromise given confirmed in-the-wild exploitation.

9.125%
  • Adobe Commerce (Magento)
mass≈200,000+ Magento/Adobe Commerce storefronts worldwide
Full article216 words · extracted from securityaffairs.com · click to collapse

Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data.

Hackers began targeting CVE-2026-71362 (CVSS score of 9.1), a critical Adobe Commerce flaw, shortly after its public disclosure. The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data.

Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory. The flaw affects Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches. Adobe released an isolated fix and urged users to patch.

“Adobe has released APSB26-92 as isolated patch files. The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9.1. Sansec Shield already blocks exploitation attempts.” reads the advisory published by Sansec. “Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data.”

Sansec pointed out that an attacker can exploit the flaw without existing account, administrator privileges, or user interaction.

Adobe fixed how Magento handles customer identity in account sessions. The remaining flaws include stored cross-site scripting and authorization issues.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Adobe)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/197149/hacking/adobe-commerce-cve-2026-71362-comes-under-attack-shortly-after-public-disclosure.html