Patch released Adobe Commerce auth-bypass Magento Open Source Adobe web-app
Adobe Commerce Bug Targeted Immediately After Disclosure
CVE Tools coverage
Adobe has released a security update to address CVE-2026-71362, a critical authorization flaw affecting Adobe Commerce and Magento Open Source that was rapidly targeted following its public disclosure. With a CVSS score of 9.1, this vulnerability allows unauthenticated remote attackers to hijack customer sessions and access private data by switching account identities. Although Adobe reported no prior in-the-wild exploitation before the advisory, security firm Sansec confirmed they intercepted initial exploitation attempts shortly after the bug was made public. The fix modifies how customer identity is handled in sessions and applies to all versions up to and including the July 2026 patches.