Cybersecurity firm Sansec reports that hackers are actively exploiting a critical Adobe Commerce flaw (CVE-2026-71362) following its public disclosure. The vulnerability allows unauthenticated attackers to hijack customer accounts.

Key Takeaways

  • CVE-2026-71362 holds a critical CVSS score of 9.1.
  • Attackers can switch customer sessions to hijack private data.
  • The flaw affects Adobe Commerce, B2B, and Magento Open Source.
  • Adobe has released an isolated patch to mitigate the risk.

Hackers have begun targeting a fresh critical-severity vulnerability in Adobe Commerce almost immediately after its public disclosure. According to webstore security firm Sansec, exploitation attempts were detected shortly after Adobe released the necessary security patches.

Understanding CVE-2026-71362

The security defect, tracked as CVE-2026-71362, carries a severe CVSS score of 9.1. It is categorized as an incorrect authorization issue, which enables unauthenticated remote attackers to perform privilege escalation and take control of customer accounts.

Why This Matters

BozokMedia analysis shows that the speed at which threat actors move from disclosure to exploitation is shrinking. In this case, the flaw allows attackers to manipulate customer identity sessions, effectively switching from a standard session to a victim's private account. This provides unauthorized access to sensitive customer information and private data.

The window between vulnerability disclosure and active exploitation is closing faster than ever, leaving merchants with little time to react.

Adobe addressed the issue during the August 2026 Patch Tuesday, releasing an isolated patch to minimize integration risks for merchants. The vulnerability impacts all versions of Adobe Commerce, Commerce B2B, and Magento Open Source running up to the July 2026 patches.

Historical Background

E-commerce platforms like Magento have long been high-value targets for cybercriminals due to the concentrated amount of financial and personal data they hold. Historically, vulnerabilities in session management have been a recurring theme in large-scale retail data breaches.

Did You Know?: An 'isolated patch' is designed to fix a specific security hole without requiring a full system overhaul, reducing the risk of breaking existing website features.

Frequently Asked Questions

1. Which products are affected by this bug? Adobe Commerce, Commerce B2B, and Magento Open Source versions updated through July 2026 are at risk.

2. How can I protect my store? Merchants should immediately apply the isolated security patch provided by Adobe in the August 2026 update.