Attempts to exploit CVE-2026-71362 in Adobe Commerce and Magento have already been detected, and the bug matters because it appears to let attackers switch a live customer session into another customer’s account.
That is a very different problem from a generic storefront bug. If exploitation succeeds, the blast radius is not just application uptime. It is customer identity, stored data, order history, and trust.
What Changed
Adobe described CVE-2026-71362 as an incorrect-authorization flaw that can grant elevated access to sensitive resources without authentication. Sansec says exploitation requires no existing account, no admin privileges, and no user interaction, and its WAF is already blocking live attempts.
Stay Current on Cyber Policy and Guidance
Track new CISA actions, regulations, guidance, and risk trends in a quick daily format.
Weekday mornings. Built from 100+ trusted cybersecurity sources.
After reviewing Adobe’s patch, Sansec concluded that the bug stems from improper handling of customer identity in an account session. In practice, that means an attacker may be able to pivot one customer session into another user’s account and gain access to private customer data.
Adobe fixed six other Commerce-related issues in the same release, including multiple high-severity authorization and stored XSS bugs, but CVE-2026-71362 is the priority because it combines unauthenticated reachability with customer-account impact.
Why CyberExperts Flagged It
This is not a patch-when-convenient Commerce update. It is the kind of flaw that turns into customer-account takeover, privacy exposure, and incident-response pressure while a store still appears to be functioning normally.
Commerce teams also face an extra operational wrinkle here: Sansec says the fix arrives as an isolated patch, not a new Composer package or full release, and merchants need to be on the latest supported -p branch before applying it. That increases the odds of delay if ownership between engineering, hosting, and storefront operations is fuzzy.
What Teams Should Do Next
- Identify every Adobe Commerce, Commerce B2B, and Magento instance you still run, including lower-visibility regional or brand storefronts.
- Confirm each instance is on the latest supported
-prelease for its branch, then apply the August 2026 isolated patch that contains the CVE-2026-71362 fix. - Review logs and telemetry for suspicious customer-session changes, anomalous login-to-account transitions, or support complaints that could indicate session hijacking rather than normal fraud.
- If patching must wait, tighten monitoring immediately around customer account access, session handling, and WAF detections related to the flaw.
- Treat this as a customer-trust risk, not just an application-security ticket. Legal, support, and e-commerce stakeholders may need early awareness if you have exposed stores.
Source context: CyberExperts is using BleepingComputer as the primary reference for this update, including details attributed there to Sansec and Adobe’s August 2026 advisory.
See this item in The 5-Minute Cyber Brief