Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Attempts to exploit CVE-2026-71362 in Adobe Commerce and Magento are being blocked by Sansec’s Shield WAF, even though Adobe says it is not aware of active exploitation in the wild. The flaw can let attackers hijack customer sessions and access private account data without authentication, while Adobe has also patched six additional vulnerabilities in the same update. #AdobeCommerce #Magento #CVE-2026-71362 #Sansec

Keypoints

  • CVE-2026-71362 is a critical incorrect-authorization flaw in Adobe Commerce and Magento.
  • Attackers may hijack customer sessions and access sensitive account data.
  • Sansec says its Shield WAF is already blocking exploitation attempts.
  • The exploit requires no existing account, administrator privileges, or user interaction.
  • Adobe also fixed six other vulnerabilities in its latest security update.

Read More: https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts/