Attackers are already probing a critical Adobe Commerce flaw that lets them hop into shoppers' accounts

CVE-2026-71362 needs no login, no admin rights and no clicks from the victim. Sansec says its firewall is already blocking live exploitation attempts.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Adobe patched CVE-2026-71362, a critical flaw in Adobe Commerce and Magento, in its August 2026 security update.
  • The bug lets an attacker switch their own session over to another shopper's account, with no password, no admin rights and no clicks from the victim.
  • Security firm Sansec says its web application firewall is already blocking exploitation attempts, despite Adobe stating it has seen none in the wild.
  • Six other flaws were fixed in the same update, four of them rated high severity.
  • Store owners running Adobe Commerce, Commerce B2B or Magento need to install the isolated patch file for their release line now.

Attackers are already trying to break into Adobe Commerce and Magento stores through a newly disclosed flaw that hands them full access to shoppers' accounts.

The bug is tracked as CVE-2026-71362. Adobe rates it critical. It is what security people call an "incorrect authorization" flaw, which in plain English means the software fails to properly check who you are before letting you in.

And the check it fails is a serious one. An attacker does not need an existing account. They do not need admin rights. The victim does not have to click anything.

What does the flaw actually let attackers do?

It lets them steal shopper accounts. Dutch e-commerce security firm Sansec, which reviewed Adobe's patch, says the bug lets an attacker switch their own browser session over to a different customer's account. Once inside, they can see order history, saved addresses, stored payment details and anything else the real customer could see.

Magento, the software underneath Adobe Commerce, was mishandling how it tracked which customer a session belonged to. Fix that check, and the door closes.

Is anyone actually being attacked yet?

Probably yes. Adobe's advisory says it is not aware of exploits in the wild. Sansec disagrees: the company told BleepingComputer that its Shield web application firewall, the filter that sits in front of a shop and blocks bad requests, is already stopping attempts to trigger CVE-2026-71362.

That gap matters. Vendors often only learn about live exploitation after a customer reports a breach, which can be weeks later.

What else was patched?

Adobe fixed six other bugs in the same August 2026 update. Four are rated high severity, one medium, one low.

CVE Severity What it does Needs login?
CVE-2026-71362 Critical Session takeover of any customer account No
CVE-2026-48413 High (8.7) Stored XSS leading to code execution Yes, non-admin
CVE-2026-48414 High (7.7) Stored XSS leading to code execution Yes, admin
CVE-2026-48415 High (7.6) Security bypass in Commerce B2B Yes, non-admin
CVE-2026-48416 High (7.5) Security bypass No
CVE-2026-48411 Medium (6.5) Security bypass Yes, admin

Stored XSS, or cross-site scripting, means an attacker plants malicious code in the site itself so it runs in someone else's browser later.

How do store owners fix it?

Install the patch. Adobe distributes these monthly fixes as isolated patch files rather than a fresh full release, so administrators need to be on the latest -p release for their supported branch first, then apply the patch on top. Sansec has flagged this as a common stumbling block.

Supported release lines for Commerce, Commerce B2B and Magento all have a patch available.

What should shoppers do?

If you have an account on a store you know is built on Adobe Commerce or Magento, and there are a lot of them, treat this as a good moment to change the password on that account. Use a different password from the one you use on email or banking. Watch your card statement for the next few weeks for small unexpected charges, which are often the first sign someone has your details.

If the store you shop at issues a breach notice under GDPR, the UK Data Protection Act or a US state law, take it seriously and follow whatever specific steps the retailer lists.

© 2026 Threat Vectr