Hackers began exploiting a critical Adobe Commerce flaw, CVE-2026-71362, almost immediately after Adobe publicly disclosed the issue and issued a patch. Sansec says the vulnerability lets unauthenticated attackers hijack customer sessions and access private account data, affecting Adobe Commerce, Commerce B2B, and Magento Open Source. #CVE-2026-71362 #AdobeCommerce #MagentoOpenSource
Keypoints
- Sansec blocked the first exploitation attempts soon after Adobe’s advisory.
- CVE-2026-71362 is a critical authorization flaw with a CVSS score of 9.1.
- Unauthenticated attackers can switch a customer session to another account.
- The flaw affects Adobe Commerce, Commerce B2B, and Magento Open Source.
- Adobe released an isolated patch and urged merchants to update immediately.
Read More: https://www.securityweek.com/adobe-commerce-bug-targeted-immediately-after-disclosure/