Breaking
SecurityDeveloping Story

Commerce Flaw Hit in Hours

Adobe Commerce bug CVE-2026-71362 was exploited within hours of disclosure; Sansec reports active attacks.

··2 hours ago·3 min read
Matrix movie still
Photo by Markus Spiske on Unsplash

Within hours of Adobe publishing a patch for a critical flaw in its Commerce platform, attackers were already probing the vulnerability, according to webstore security firm Sansec. The speed of the first exploitation attempts underscores the stakes for the thousands of online merchants running the affected software.

Critical Flaw, Quick Exploitation

Tracked as CVE-2026-71362 with a CVSS score of 9.1, the vulnerability is described as an incorrect authorization issue. It allows unauthenticated attackers to elevate their privileges, a serious risk for any e-commerce operation.

Sansec, which tracks webstore threats, said it blocked the first exploitation attempts shortly after Adobe's advisory was published. The researchers reviewed the patch and confirmed the flaw's danger.

“Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data,”

— Sansec, a webstore security firm, as noted in their research.

Account Takeover Mechanics

According to Sansec, the flaw can be exploited by remote, unauthenticated attackers to take over other customer accounts. Specifically, it allows an attacker to switch a customer session to another customer account, granting access to the victim's account and private customer data.

Adobe resolved the underlying issue by modifying how Commerce and Magento handle customer identity in account sessions, Sansec explains.

Affected Versions and Patches

The vulnerability impacts all Commerce, Commerce B2B, and Magento Open Source versions up to and including those running the July 2026 patches. Adobe rolled out an isolated patch on Tuesday, August 2026 Patch Tuesday, to fix the critical flaw and six other security defects in all three products.

The company also published installation instructions for the patch. Adobe noted that the isolated patch “allows merchants to apply the fix in isolation with fewer risks of delay due to potential integration issues.”

Immediate Attack Activity

Sansec reported that it blocked the first exploitation attempts targeting the vulnerability shortly after Adobe's advisory was published. The quick turnaround from disclosure to exploitation is a reminder that threat actors actively monitor security advisories for new vulnerabilities to attack.

Adobe said it had no evidence of in-the-wild exploitation at the time of patching, but warned that threat actors have targeted Commerce before.

Response and Mitigation

Adobe urges merchants to apply the latest security updates as soon as possible. “Please apply the latest security updates as soon as possible. Successful exploitation of these vulnerabilities could lead to arbitrary code execution, security feature bypass, and privilege escalation,” the company notes.

For merchants who cannot immediately patch, Adobe has provided an isolated patch that can be applied without waiting for a full release cycle. This is part of a broader effort to help businesses protect their customer data in the face of active threats.

Why This Matters for Your Store

For any business running Adobe Commerce, Magento Open Source, or Commerce B2B, this vulnerability is a direct threat to customer data and account integrity. The fact that attackers are already exploiting it means that delaying a patch is not a safe option.

This could mean that any e-commerce site running an affected version is at risk of customer account takeover. Given the speed of the attacks, merchants should treat this as an urgent priority and apply the isolated patch without delay. The potential impact on customer trust and legal liabilities makes proactive patching a critical business decision.

#adobe commerce#cve-2026-71362#sansec#patch tuesday#vulnerability

Sources

Iliyas

Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories