Particle.news

Critical Adobe Commerce Flaw Lets Attackers Hijack Customer Accounts

Security firm detections show active targeting that raises urgent risk for unpatched storefronts worldwide.

Overview

  • Adobe published an isolated August 2026 security patch on Patch Tuesday that fixes CVE-2026-71362 along with six other vulnerabilities and provided installation guidance for administrators.
  • CVE-2026-71362 is an incorrect-authorization bug with a CVSS score of 9.1 that lets unauthenticated attackers switch a customer session to another account and access private customer data.
  • Sansec reviewed Adobe’s fix and reported that its Shield web application firewall began blocking exploitation attempts shortly after the advisory was published, indicating attackers started targeting the flaw immediately.
  • Adobe distributes these monthly fixes as isolated patch files that require sites to be on the correct -p release branch and to apply patches in the right order, so administrators must follow the vendor instructions precisely and update now.
  • The flaw affects Adobe Commerce, Commerce B2B, and Magento Open Source versions through the July 2026 patches and is especially dangerous because it needs no user interaction or existing account, increasing the risk of data theft, fraud, and reputational damage for online stores.