Exploited in the wild Adobe Commerce web-app Magento Open Source Adobe auth-bypass
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
CVE Tools coverage
Attackers are actively exploiting a critical incorrect authorization vulnerability, CVE-2026-71362, in Adobe Commerce and Magento platforms to hijack customer accounts without requiring authentication or administrative privileges. Security firm Sansec confirmed that their WAF is already blocking these attempts, noting that the flaw allows attackers to switch a customer session to another account. This issue was part of a security update released alongside six other vulnerabilities, including high-severity XSS flaws like CVE-2026-48413 and CVE-2026-48414. Administrators should apply the isolated August 2026 patch files after ensuring they have installed the latest point release for their specific supported version.