Critical Adobe Commerce Flaw Exploited in the Wild, Threatening Customer Accounts
A critical vulnerability, **CVE-2026-71362**, affecting **Adobe Commerce** and **Magento** e-commerce platforms is actively being exploited, allowing attackers to hijack customer accounts. Despite **Adobe**'s initial assessment of no in-the-wild exploitation, security firm **Sansec** has confirmed blocking attempts.
E-commerce platforms powered by **Adobe Commerce** and **Magento** are currently facing an active threat due to the exploitation of a critical vulnerability, **CVE-2026-71362**.

This flaw, described as an incorrect authorization vulnerability, enables attackers to gain elevated access to sensitive resources without requiring authentication. While **Adobe**'s security advisory indicated no awareness of in-the-wild exploits for any of the seven issues addressed in their latest security update, e-commerce security company **Sansec** reports that its Shield web application firewall (WAF) is already detecting and blocking exploitation attempts.
### The Mechanics of the Attack
**Sansec**'s analysis of **Adobe**'s patch revealed that the vulnerability stems from **Magento** improperly handling customer identity within an account session. Critically, exploiting **CVE-2026-71362** requires no existing account, administrator privileges, or user interaction.
According to **Sansec** researchers, "the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim's account and private customer data."
### Other Vulnerabilities Addressed
In addition to **CVE-2026-71362**, **Adobe**'s recent security update addressed six other vulnerabilities, four of which were rated as high severity:
* **CVE-2026-48414** (7.7, high severity): A stored cross-site scripting (XSS) vulnerability potentially leading to arbitrary code execution, requiring authentication and administrator privileges.
* **CVE-2026-48413** (8.7, high severity): Another stored XSS vulnerability that could result in arbitrary code execution, requiring authentication but not administrator privileges.
* **CVE-2026-48415** (7.6, high severity): An incorrect-authorization vulnerability impacting **Adobe Commerce B2B** that could bypass security features, requiring authentication but not administrator privileges.
* **CVE-2026-48416** (7.5, high severity): An incorrect-authorization vulnerability enabling a security-feature bypass, requiring neither authentication nor administrator privileges.
* **CVE-2026-48411** (6.5, medium severity): An incorrect-authorization vulnerability that could bypass security features, requiring authentication and administrator privileges.
* **CVE-2026-48412** (2.7, low severity): An incorrect-authorization vulnerability potentially leading to privilege escalation, requiring authentication and administrator privileges.
### Immediate Action Required
Website administrators managing **Commerce**, **Commerce B2B**, and **Magento** installations are strongly advised to apply the August 2026 security update as soon as possible. **Sansec** notes that these monthly fixes are distributed as isolated patch files rather than full security releases or updated Composer packages.
Admins must ensure their systems are running the latest `-p` release available for their supported branch before applying the corresponding isolated patch to mitigate these risks effectively.