Adobe Commerce Flaw Hit by Immediate Exploitation Attempts

Sansec blocked the first exploitation attempts against Adobe Commerce CVE-2026-71362 shortly after Adobe’s August 2026 Patch Tuesday disclosure. Adobe said the critical incorrect-authorization flaw affects Commerce, Commerce B2B, and Magento Open Source, including systems still on July 2026 patches. The bug lets an unauthenticated attacker switch a live customer session onto another account. Once that happens, the attacker inherits that customer’s access and private data, so the problem is account takeover and data exposure, not just a vulnerable storefront server. For merchants running Adobe’s commerce stack, the exposure sits in customer sessions already issued before the fix lands, and patched software does not undo what a live session may already have revealed. If the platform handles customer identities across storefront and back-end services, the trust break can carry straight into account fraud and data resale.

Part of the PlainSec briefing for 2026-08-13

Editions

Sources