Attempts to exploit a critical vulnerability (CVE‑2026‑71362) in Adobe's Commerce and Magento platforms have been detected, potentially allowing attackers to hijack customer accounts.

Key Takeaways

  • Critical vulnerability found in Adobe Commerce and Magento
  • Attackers can hijack customer accounts
  • Adobe released an urgent security update

Attempts to exploit a critical vulnerability (CVE‑2026‑71362) in Adobe's Commerce and Magento e‑commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. The flaw is an incorrect‑authorization issue that grants elevated access to sensitive resources without authentication.

What Is This Vulnerability?

The issue stems from Magento mishandling customer identity within an account session. Exploiting it lets an attacker switch a victim’s session to another customer’s account, exposing private data.

Why This Matters

BozokMedia analysis shows that such unauthorized session swaps can lead to massive data breaches across thousands of online stores, eroding consumer trust and exposing businesses to legal liabilities.

"This vulnerability is extremely serious and can be exploited without any authentication."

Security Update

Adobe has issued a patch addressing the flaw. Website administrators should apply the August 2026 security update immediately to mitigate the risk.

Did You Know?: These types of flaws are often exploited automatically, without any user interaction.

Frequently Asked Questions

  • Does this vulnerability affect only Adobe Commerce?
  • Has Adobe released a patch for this issue?