Attackers have begun targeting CVE-2026-71362, a critical incorrect-authorization flaw in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that can let unauthenticated users hijack customer accounts. Sansec reported seeing exploitation attempts blocked by its Shield WAF and said patch analysis showed Magento mishandles customer identity within an account session, allowing a session to be switched to another customer account and exposing private customer data.
Adobe included fixes for CVE-2026-71362 in its August 2026 security updates, with affected versions spanning multiple July 2026 and some August 2026 release lines before newer August builds. The same update also addressed CVE-2026-48413, a stored XSS issue, along with six additional Commerce and Commerce B2B vulnerabilities, four rated high severity. Administrators were urged to move to the latest supported -p release and apply Adobe’s isolated patches promptly to reduce the risk of account takeover and data exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In its advisory for the August 2026 fixes, Adobe stated it was not aware of exploits in the wild for any of the patched vulnerabilities. This included the critical incorrect-authorization flaw CVE-2026-71362.
Adobe addressed seven vulnerabilities in an August 2026 security update for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, including CVE-2026-71362 and CVE-2026-48413. The fixed version boundaries indicate August 2026 builds as unaffected across the supported product branches.
After analyzing Adobe's patch, Sansec said Magento improperly handles customer identity in an account session, allowing attackers to switch a session to another customer's account. Successful exploitation could expose private customer data and enable customer account hijacking.
Sansec reported that its Shield web application firewall was already blocking attempts to exploit CVE-2026-71362. The company said the flaw can be targeted without an existing account, administrator privileges, or user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcesansec.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.