Attempts to exploit a critical vulnerability in Adobe Commerce and Magento e-commerce platforms have been detected, raising concerns that attackers could use the flaw to hijack customer accounts.

The vulnerability, tracked as CVE-2026-71362, is described as an incorrect authorization issue that could allow attackers to gain elevated access to sensitive resources without authentication. It is one of seven vulnerabilities addressed by Adobe in its latest security update.

Adobe said in its security advisory that it was not aware of exploits in the wild targeting any of the vulnerabilities fixed in the update. However, e-commerce security company Sansec says its Shield web application firewall is already blocking attempts to exploit CVE-2026-71362.

According to Sansec, exploiting the vulnerability does not require an existing account, administrator privileges or any interaction from the victim.

After analyzing Adobe’s security patch, Sansec researchers found that the vulnerability is related to how Magento handles customer identities within account sessions. The flaw could allow an attacker to switch a customer session to another customer’s account, giving them access to the victim’s account and private customer information.

Adobe’s latest update also fixes six other vulnerabilities across its Commerce, Commerce B2B and Magento platforms. Four of those flaws are rated high severity, while one is rated medium severity and another is rated low severity.

CVE-2026-48414 has a CVSS score of 7.7 and is a high-severity stored cross-site scripting vulnerability that could potentially lead to arbitrary code execution. Exploitation requires authentication and administrator privileges.

READ
FBI Warns Cybercriminals Are Stealing Intimate Photos From Online Accounts

CVE-2026-48413 carries a CVSS score of 8.7 and is another high-severity stored cross-site scripting vulnerability that could result in arbitrary code execution. It requires authentication but does not require administrator privileges.

CVE-2026-48415 has a CVSS score of 7.6 and affects Adobe Commerce B2B. The high-severity incorrect-authorization vulnerability could allow a security-feature bypass. Exploitation requires authentication but not administrator privileges.

CVE-2026-48416 has a CVSS score of 7.5 and is an incorrect-authorization vulnerability that could also allow a security-feature bypass. The flaw can reportedly be exploited without authentication or administrator privileges.

CVE-2026-48411 is rated medium severity with a CVSS score of 6.5. It is an incorrect-authorization vulnerability that could allow a security-feature bypass, although exploitation requires authentication and administrator privileges.

CVE-2026-48412 is rated low severity with a CVSS score of 2.7. The incorrect-authorization vulnerability could potentially lead to privilege escalation and requires authentication and administrator privileges to exploit.

Website administrators are advised to install the August 2026 security update for supported Adobe Commerce, Commerce B2B and Magento release lines as soon as possible.

According to Sansec, Adobe distributes these monthly fixes as isolated patch files rather than releasing them as a new security release or updated Composer packages.


Buy ExpressVPN with PayPal or Credit Card

Before applying the relevant isolated patch, website administrators must ensure their installations are running the latest -p release available for their supported release branch.

Advertisement