Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Hackers are exploiting a critical vulnerability in Adobe Commerce and Magento e-commerce platforms, potentially allowing them to hijack customer accounts. The bug, identified as CVE-2026-71362, is an incorrect authorization vulnerability that can be leveraged without authentication or administrator privileges. This means that attackers do not need to have existing account information or interact with users to gain access to sensitive resources.

The security flaw was one of seven issues addressed by Adobe in a recent security update, but despite the vendor’s claims that it has not seen any exploits in the wild for these flaws, eCommerce security company Sansec is already detecting attempts to exploit CVE-2026-71362. According to Sansec, exploiting this vulnerability requires no prior knowledge or interaction with the affected platform, making it a particularly concerning issue.

Sansec researchers analyzed Adobe’s patch and determined that the root cause of the problem lies in Magento’s handling of customer identity during an account session. Specifically, they found that attackers can switch a customer session to another customer account, granting them access to sensitive information such as private customer data.

In addition to CVE-2026-71362, four other flaws addressed by Adobe’s recent update received high-severity scores, including two cross-site scripting vulnerabilities (CVE-2026-48413 and CVE-2026-48414) that can result in arbitrary code execution. Two more vulnerabilities (CVE-2026-48415 and CVE-2026-48416) are incorrect-authorization issues that can enable security-feature bypasses without requiring authentication or administrator privileges.

Adobe’s patches for these vulnerabilities were released as isolated patch files, rather than a new security release or updated Composer packages. Website administrators are advised to apply the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible. To do this, they must first ensure that their platform is running the latest -p release available for their supported branch.

The exploitation of CVE-2026-71362 highlights the importance of regular security updates and patching. With hackers increasingly targeting vulnerable e-commerce platforms, website administrators must stay vigilant and prioritize security to protect customer data.


Source: Bleeping Computer — 2026-08-12