Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

By George Bailey   Published: 08/12/26   Updated: 08/12/26   3 min read

Attempts to exploit CVE-2026-71362 in Adobe Commerce and Magento have already been detected, and the bug matters because it appears to let attackers switch a live customer session into another customer’s account.

That is a very different problem from a generic storefront bug. If exploitation succeeds, the blast radius is not just application uptime. It is customer identity, stored data, order history, and trust.

What Changed

Adobe described CVE-2026-71362 as an incorrect-authorization flaw that can grant elevated access to sensitive resources without authentication. Sansec says exploitation requires no existing account, no admin privileges, and no user interaction, and its WAF is already blocking live attempts.

After reviewing Adobe’s patch, Sansec concluded that the bug stems from improper handling of customer identity in an account session. In practice, that means an attacker may be able to pivot one customer session into another user’s account and gain access to private customer data.

Adobe fixed six other Commerce-related issues in the same release, including multiple high-severity authorization and stored XSS bugs, but CVE-2026-71362 is the priority because it combines unauthenticated reachability with customer-account impact.

Why CyberExperts Flagged It

This is not a patch-when-convenient Commerce update. It is the kind of flaw that turns into customer-account takeover, privacy exposure, and incident-response pressure while a store still appears to be functioning normally.

Commerce teams also face an extra operational wrinkle here: Sansec says the fix arrives as an isolated patch, not a new Composer package or full release, and merchants need to be on the latest supported -p branch before applying it. That increases the odds of delay if ownership between engineering, hosting, and storefront operations is fuzzy.

What Teams Should Do Next

Source context: CyberExperts is using BleepingComputer as the primary reference for this update, including details attributed there to Sansec and Adobe’s August 2026 advisory.

See this item in The 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.

Keep Reading