A critical vulnerability in Adobe Commerce, identified as CVE-2026-71362, has been exploited by hackers shortly after its public disclosure, allowing unauthenticated attackers to hijack customer accounts and access sensitive data1. This flaw, which has a CVSS score of 9.1, enables attackers to switch customer sessions, potentially leading to unauthorized access to private information. The vulnerability affects various versions of Commerce, Commerce B2B, and Magento Open Source. Cybersecurity firm Sansec has reported blocking the first exploitation attempts following Adobe's advisory publication. The swift exploitation of this vulnerability highlights the importance of prompt patching and monitoring. This vulnerability expansion of the active attack surface matters to practitioners, as it necessitates prioritization based on exposure and exploitation evidence, underscoring the need for swift remediation to prevent potential breaches.