Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure
Brief
Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data.
Hackers began targeting CVE-2026-71362 (CVSS score of 9. 1), a critical Adobe Commerce flaw, shortly after its public disclosure . The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data.
Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory. The flaw affects Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches . Adobe released an isolated fix and urged users to patch.
“Adobe has released APSB26-92 as isolated patch files. The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9.
- Sansec Shield already blocks exploitation attempts.”
