A critical vulnerability in Adobe Commerce, identified as CVE-2026-71362, has been exploited by hackers shortly after its public disclosure, allowing unauthenticated attackers to hijack customer accounts and access sensitive data1. This flaw, which has a CVSS score of 9.1, enables attackers to switch customer sessions, potentially leading to unauthorized access to private information. The vulnerability affects various versions of Commerce, Commerce B2B, and Magento Open Source. Cybersecurity firm Sansec has reported blocking the first exploitation attempts following Adobe's advisory publication. The swift exploitation of this vulnerability highlights the importance of prompt patching and monitoring. This vulnerability expansion of the active attack surface matters to practitioners, as it necessitates prioritization based on exposure and exploitation evidence, underscoring the need for swift remediation to prevent potential breaches.
Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure
⚠️ Critical Alert
Why This Matters
CVE-2026-71362 disclosure expands the active attack surface — prioritize based on your exposure and exploitation evidence.
References
- SecurityAffairs. (2026, August 13). Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure. *SecurityAffairs*. https://securityaffairs.com/197149/hacking/adobe-commerce-cve-2026-71362-comes-under-attack-shortly-after-public-disclosure.html
Original Source
SecurityAffairs
Read original →