Sansec detects attempts to exploit critical Adobe Commerce flaw
This digest was compiled by AI from multiple sources — links to the originals are below.

Sansec says its Shield web application firewall is blocking attempts to exploit CVE-2026-71362, an incorrect authorization flaw in Adobe Commerce and Magento that can let attackers switch customer sessions. Adobe patched the flaw in its August 2026 security update but says it is not aware of in-the-wild exploitation. Sansec says exploitation requires no existing account, administrator privileges, or user interaction.
Vulnerability Details
CVE-2026-71362 is rated critical by Adobe and stems from Magento improperly handling customer identity in an account session. Sansec analyzed the patch and confirmed the flaw lets attackers switch a customer session to another customer account, exposing private customer data. The attack requires no existing account, administrator privileges, or user interaction. Adobe addressed the flaw as one of seven vulnerabilities in the update.
Patch and Distribution
Adobe released the fixes on August 12, 2026, covering currently supported Adobe Commerce, Commerce B2B, and Magento release lines. Sansec noted the monthly fixes are distributed as isolated patch files rather than a new security release or updated Composer packages. Website administrators must first run the latest -p release for their supported branch before applying the corresponding patch.
Other Fixed Flaws
Four other vulnerabilities fixed in the update received high-severity ratings. CVE-2026-48413, rated 8.7, is a stored cross-site scripting flaw requiring authentication; CVE-2026-48414 at 7.7 requires authentication and administrator privileges. CVE-2026-48415 at 7.6 affects Adobe Commerce B2B, and CVE-2026-48416 at 7.5 requires no authentication or administrator privileges. CVE-2026-48411 and CVE-2026-48412 are rated medium and low severity.
What's Next
Adobe Commerce and Magento administrators are expected to apply the August 2026 isolated patches as soon as possible, with no updated Composer packages provided. It remains unclear whether attackers have already used the flaw to hijack customer accounts, as Adobe has not confirmed in-the-wild exploitation.
1 source
Sansec detects attempts to exploit critical Adobe Commerce flaw



