CVE Tools

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

BleepingComputerBy Bill Toulas

Reported exploitedAdobe CommerceMagento Open Source

Our summary

Attackers are actively exploiting a critical incorrect authorization vulnerability, CVE-2026-71362, in Adobe Commerce and Magento platforms to hijack customer accounts without requiring authentication or administrative privileges. Security firm Sansec confirmed that their WAF is already blocking these attempts, noting that the flaw allows attackers to switch a customer session to another account. This issue was part of a security update released alongside six other vulnerabilities, including high-severity XSS flaws like CVE-2026-48413 and CVE-2026-48414. Administrators should apply the isolated August 2026 patch files after ensuring they have installed the latest point release for their specific supported version.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store