Adobe Commerce CVE-2026-71362: Account Takeover
A critical CVSS 9.1 flaw in Adobe Commerce and Magento lets unauthenticated attackers hijack customer accounts. Exploitation began right after disclosure.
Another critical e-commerce flaw is being weaponized within days of its fix. Adobe has patched CVE-2026-71362, an incorrect authorization vulnerability in Adobe Commerce and Magento Open Source that lets an unauthenticated attacker take over customer accounts. The bug carries a CVSS score of 9.1, and security firm Sansec says exploitation attempts began arriving shortly after public disclosure — the company reports its Shield web application firewall is already blocking probes against the flaw.
Adobe Commerce (formerly Magento Commerce) and its open-source sibling power a large share of the world’s online storefronts. A pre-authentication account-takeover bug in that kind of platform is a direct threat to shoppers’ data and to the merchants who host it, and Magento’s history of fast, mass exploitation makes the short runway on this one especially dangerous.
The vulnerability
CVE-2026-71362 is an improper authorization weakness — classified as CWE-863 — that stems from the platform failing to correctly bind a customer’s identity to their account session. After analyzing Adobe’s patch, researchers traced the root cause to Magento mishandling customer identity within an account session, a flaw that lets an attacker end up acting as a user who isn’t them.
The exploitation profile is what makes it critical. According to Adobe’s advisory, an attacker needs no existing account, no administrator privileges, and no user interaction to abuse the flaw. It is exploitable over the network without credentials, which is exactly the combination — network access, low complexity, no privileges required — that pushes the CVSS score to 9.1. Successful exploitation gives an attacker elevated access to sensitive resources, up to and including hijacking the accounts of a store’s customers.
Session-identity flaws are a recurring class of web bug: when an application doesn’t rigorously tie the authenticated identity to the session token presented on each request, an attacker can slip into another user’s context. The mechanics differ from classic session fixation, but the outcome is the same — the server trusts a session it shouldn’t, and hands over data or privileges accordingly.
Affected versions and the fix
Adobe resolved CVE-2026-71362 as part of its August 2026 Patch Tuesday security release. The flaw affects all Adobe Commerce, Commerce B2B, and Magento Open Source builds up to and including those running the July 2026 patches — a broad population that includes any store that hadn’t applied the newest updates.
Adobe’s advisory initially stated it had no evidence of in-the-wild exploitation at the time of release, while noting that threat actors have repeatedly targeted Commerce in the past. That caveat proved prescient: within a short window of disclosure, Sansec observed the first exploitation attempts and began blocking them at the web application firewall layer. Merchants should treat patching as urgent:
- Apply the August 2026 security update for Adobe Commerce / Magento immediately, and confirm the running build reflects the fixed version rather than assuming a deploy succeeded.
- Front the storefront with a WAF capable of blocking the exploitation pattern as an interim shield while the patch is rolled out across staging and production.
- Review logs for anomalous account activity — unexpected logins, session reuse across IP addresses, and access to customer data that doesn’t match normal behavior.
- Invalidate active customer sessions after patching if compromise is suspected, forcing re-authentication so any hijacked sessions are cut off.
From disclosure to attack in days
The timeline is the story. Adobe shipped the fix, and almost immediately researchers began seeing attempts to exploit it — before most merchants could realistically have patched. When exploitation appears this fast, it typically means attackers reverse-engineered the vendor’s patch to reconstruct the vulnerable code path, a technique known as patch diffing that has become standard practice against high-value targets.
Magento is a perennial favorite for exactly this reason. The platform has a long line of severe, widely exploited vulnerabilities — from Shoplift (2015) and TrojanOrder (2022) to CosmicSting (CVE-2024-34102) and last year’s SessionReaper (CVE-2025-54236), an unauthenticated RCE that exposed thousands of stores to automated attacks. CVE-2026-71362 lands in that lineage. Attackers already run tooling that scans the internet for vulnerable Magento instances and fires exploits automatically, so the gap between “patch published” and “stores compromised” is measured in days, not weeks.
That pattern echoes the broader wave of enterprise-software exploitation this year, from the max-severity SAP Commerce Cloud RCE to the Adobe ColdFusion remote code execution flaw and the VMware vCenter campaign that went from disclosure to active abuse in under a week. In each case, the vulnerable software sits at the core of business operations, and defenders are racing the same clock.
Why e-commerce platforms keep getting hit
Online stores are a uniquely attractive target: they process payments, store personal and financial data, and must stay reachable on the public internet by design. A Magento compromise opens several lucrative paths at once — skimming payment-card data by injecting malicious JavaScript into checkout pages, harvesting customer records for resale, and using the foothold as a pivot into back-office systems.
Account takeover specifically is valuable because it doesn’t always trip the alarms a full server compromise would. An attacker operating inside legitimate customer accounts can access order histories, saved addresses, stored payment references, and loyalty balances — and can do so quietly, blending in with normal traffic. For merchants, that raises the stakes on detection: the damage from CVE-2026-71362 may not look like an intrusion so much as a wave of “customers” behaving slightly wrong.
The recurring root cause across these incidents is the same one seen in this year’s other e-commerce and enterprise bugs: powerful functionality reachable without a properly enforced authorization check. It is the web-application analogue of the flaws catalogued in the OWASP Top 10, and it keeps surfacing because complex, long-lived commerce codebases accumulate exactly these kinds of trust gaps.
What it means
A pre-auth, CVSS 9.1 account-takeover bug in Adobe Commerce and Magento, already drawing exploitation attempts, is a same-week emergency for anyone running an affected store — not a next-maintenance-window item.
Why the speed matters. The defining feature of this flaw isn’t just its severity; it’s the near-zero gap between disclosure and attack. Merchants who wait for a convenient patch window are effectively racing automated exploit tooling that never sleeps. The population of exposed stores is large — everything up to and including the July 2026 patch level — and Magento’s install base skews toward small and mid-size merchants that patch slowly, which is precisely the cohort attackers count on.
Who is exposed. Any retailer or B2B seller running Adobe Commerce, Commerce B2B, or Magento Open Source without the August 2026 update, reachable from the public internet, is in the immediate risk pool. Because the payoff is customer accounts and payment flows, a successful takeover threatens both shopper data and the merchant’s regulatory and reputational standing.
What to watch. First, whether exploitation broadens from Sansec’s early probes into confirmed, large-scale account-takeover campaigns and card-skimming — the usual trajectory once a Magento flaw is understood. Second, how fast a public proof-of-concept circulates; its appearance historically triggers a sharp spike in opportunistic scanning against unpatched laggards. Third, patch uptake across the long tail of Magento stores, which is notoriously slow — the merchants still exposed a month from now will be the ones attackers harvest last. The fix is available, but with in-the-wild activity already confirmed and no public exploit yet required to trigger it, the response window for CVE-2026-71362 is measured in hours and days.
Keep reading
Chisato · · 7 min read StyleSmuggler: Magento Zero-Day RCE Under Attack
StyleSmuggler (CVE-2026-75650), a CVSS 10 zero-day in Magento and Adobe Commerce, is being used to backdoor online stores. Adobe shipped an emergency hotfix.
Chisato · · 5 min read What Is an IDN Homograph Attack?
An IDN homograph attack registers a lookalike domain using Unicode characters that resemble Latin letters. How it works, how browsers react, and defenses.
Chisato · · 5 min read What Is Envelope Encryption? Data Keys and KEKs Explained
Envelope encryption encrypts data with a data key, then encrypts that key with a master key held in a KMS. How it works, why clouds use it, and key rotation.