Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

A critical vulnerability has been discovered in Adobe’s Commerce and Magento e-commerce platforms, potentially allowing hackers to hijack customer accounts. This flaw, identified as CVE-2026-71362, is just one of seven issues addressed by Adobe in a recent security update. Despite the software vendor’s claim that it is not aware of exploits in the wild for any of the fixed flaws, a cybersecurity company has already detected attempts to exploit this vulnerability.

Sansec, an e-commerce security firm, reports that its web application firewall (WAF) is blocking exploitation attempts of CVE-2026-71362. The researchers found that exploiting this flaw requires no existing account, administrator privileges or user interaction. By analyzing Adobe’s patch, Sansec determined that the problem lies in Magento’s improper handling of customer identity in an account session.

According to Sansec, hackers can switch a customer session to another customer account using this vulnerability, granting them access to private customer data and other sensitive information. This is a significant concern for e-commerce businesses, as it allows attackers to gain unauthorized access to valuable customer data.

The good news is that Adobe has released a security update to address these vulnerabilities, including CVE-2026-71362. Website administrators are advised to apply the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible. However, it’s essential to note that this update requires website admins to ensure they’re running the latest -p release available for their supported release branch before applying the corresponding isolated patch.

In addition to CVE-2026-71362, four other flaws addressed in Adobe’s security update are classified as high-severity issues. These vulnerabilities include incorrect authorization and stored cross-site scripting (XSS) flaws that could result in arbitrary code execution or privilege escalation. While these issues require authentication and/or administrator privileges, they still pose a significant risk to e-commerce businesses.

To mitigate this risk, website administrators should prioritize applying the latest security updates and ensuring their systems are properly configured. By doing so, they can significantly reduce the likelihood of a successful attack. Remember, regular updates and proper configuration are essential for maintaining robust cybersecurity defenses in today’s online landscape.


Source: Bleeping Computer — 2026-08-12