Adobe patches critical Magento account takeover (APSB26-92)
Adobe ships isolated patches (APSB26-92) for Adobe Commerce and Magento Open Source fixing seven flaws, five Critical including account takeover CVE-2026-71362.
Adobe released isolated security patches under APSB26-92 for Adobe Commerce and Magento Open Source addressing seven vulnerabilities, five of them rated Critical. The critical set includes CVE-2026-71362, which Sansec characterizes as enabling account takeover. Merchots running Magento-based stores are urged to apply the patches.
- Seven vulnerabilities fixed, five rated Critical
- CVE-2026-71362 enables account takeover
- Isolated patches for Adobe Commerce and Magento Open Source
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-71362 | Unauthenticated Privilege Escalation Flaw in Adobe Commerce (Magento) CVE-2026-71362 is an incorrect-authorization flaw (CWE-863) in Adobe Commerce, the e-commerce platform formerly known as Magento, in which authorization checks are applied incorrectly and can be bypassed. It is triggered over the network without authentication or user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). A successful attacker gains elevated access to sensitive resources — a privilege-escalation condition that Adobe's APSB26-92 advisory and press coverage describe as an account-takeover risk. Any organization running an unpatched Adobe Commerce/Magento deployment is affected; exact version ranges are listed in Adobe security bulletin APSB26-92. The flaw came under active attack shortly after public disclosure, and its EPSS score of 25.1% (98th percentile) signals a high likelihood of continued near-term exploitation. Do: Apply the fix released under Adobe advisory APSB26-92 immediately, prioritizing internet-facing Commerce/Magento instances, and check the bulletin for the exact patched version ranges for your deployment. Because exploitation requires no credentials or user interaction, review admin accounts, API integrations, and user/role assignments for unauthorized privilege changes, and restrict admin-panel and storefront API access where feasible. Monitor Adobe's advisory for indicators of compromise given confirmed in-the-wild exploitation. | 9.1 | 25% |
| mass≈200,000+ Magento/Adobe Commerce storefronts worldwide |
Adobe has released isolated security patches for APSB26-92 for Adobe Commerce and Magento Open Source.The update fixes seven vulnerabilities. Five are rated Critical, including CVE-2026-71362, an ...
This source does not provide full text. Read it at sansec.io.