Adobe Commerce CVE-2026-71362 Exploited Within Hours of Patch Release
Hackers began exploiting a critical Adobe Commerce vulnerability almost immediately after Adobe published its patch advisory, according to webstore security firm Sansec. Tracked as CVE-2026-71362, the flaw carries a CVSS score of 9.1 and stems from an incorrect authorization issue that allows unauthenticated remote attackers to elevate their privileges on affected deployments. Adobe resolved the defect during its August 2026 Patch Tuesday cycle, releasing an isolated patch alongside fixes for six other security defects affecting Commerce, Commerce B2B, and Magento Open Source versions up to and including those running the July 2026 patches. Administrators should verify their installations immediately using a reliable privacy checkup to ensure no unauthorized session activity has occurred.
Sansec's analysis of the patch revealed that the vulnerability enables attackers to swap a customer session for another customer's account, effectively granting full access to the victim's profile and private data. Shortly after Adobe's advisory went live, the firm reported blocking the first exploitation attempts in the wild. Adobe stated it had no evidence of prior in-the-wild exploitation but warned that threat actors have historically targeted Commerce platforms, making rapid patching essential. The company modified how Commerce and Magento handle customer identity within account sessions to close the gap, and emphasized that merchants should apply the isolated patch promptly to avoid risks of arbitrary code execution, security feature bypass, and privilege escalation.
Adobe's isolated patch is designed to allow merchants to deploy the fix independently of their regular release cycle, minimizing potential integration conflicts. For organizations running affected versions, the company strongly recommends prioritizing installation and monitoring logs for suspicious session-switching activity. Security teams can bolster their detection posture by running a port scanner to identify exposed management interfaces and reviewing access controls for any anomalous authentication patterns. Given the speed at which threat actors weaponized this CVE, delay in patching could result in large-scale account takeovers and exposure of sensitive customer data across e-commerce storefronts worldwide.