Adobe Commerce Flaw Hit by Immediate Exploitation Attempts
Sansec blocked the first exploitation attempts against Adobe Commerce CVE-2026-71362 shortly after Adobe’s August 2026 Patch Tuesday disclosure. Adobe said the critical incorrect-authorization flaw affects Commerce, Commerce B2B, and Magento Open Source, including systems still on July 2026 patches.
The bug lets an unauthenticated attacker switch a live customer session onto another account. Once that happens, the attacker inherits that customer’s access and private data, so the problem is account takeover and data exposure, not just a vulnerable storefront server.
For merchants running Adobe’s commerce stack, the exposure sits in customer sessions already issued before the fix lands, and patched software does not undo what a live session may already have revealed. If the platform handles customer identities across storefront and back-end services, the trust break can carry straight into account fraud and data resale.