Adobe Commerce Bug Targeted Immediately After Disclosure, Webstore Security Firm Warns
A critical-severity vulnerability in Adobe Commerce has been exploited by hackers just hours after it was publicly disclosed, according to webstore security firm Sansec. The flaw, tracked as CVE-2026-71362 with a CVSS score of 9.1, allows unauthenticated attackers to elevate their privileges and take over other customer accounts.
The vulnerability affects all Commerce, Commerce B2B, and Magento Open Source versions up to and including those running the July 2026 patches. Sansec reports that it blocked the first exploitation attempts targeting the CVE shortly after Adobe’s advisory was published. The firm notes that the flaw lets attackers switch a customer session to another customer account, granting them access to the victim’s private customer data.
Adobe resolved the underlying issue by modifying how Commerce and Magento handle customer identity in account sessions. To fix the critical flaw and six other security defects, Adobe rolled out an isolated patch on Tuesday, which allows merchants to apply the fix in isolation with fewer risks of delay due to potential integration issues.
The rapid targeting of this vulnerability highlights the importance of prompt action when it comes to addressing security flaws. As Adobe notes, threat actors have targeted Commerce before, and the company urges merchants to apply the latest security updates as soon as possible. Successful exploitation of these vulnerabilities could lead to arbitrary code execution, security feature bypass, and privilege escalation.
In related news, a patch for WordPress 7.0.4 was released earlier this week to address a remote code execution vulnerability. Additionally, several other high-profile companies have recently issued patches for critical vulnerabilities in their products.
Adobe’s prompt action in releasing an isolated patch demonstrates the company’s commitment to addressing security flaws quickly and effectively. However, the swift targeting of this vulnerability serves as a reminder that hackers are always on the lookout for opportunities to exploit newly disclosed flaws.
To stay safe, it is essential to keep software up-to-date with the latest security patches. Merchants should apply the isolated patch released by Adobe as soon as possible to mitigate the risk of exploitation. Additionally, users should be cautious when receiving emails or notifications from unknown sources, and never click on suspicious links or download attachments from untrusted senders.
By taking proactive steps to address security vulnerabilities, individuals and organizations can significantly reduce the risk of falling victim to a successful attack. As the threat landscape continues to evolve, it is crucial to stay informed about emerging threats and take action to protect against them.
Source: SecurityWeek — 2026-08-13