
Makes an attempt to take advantage of a vital vulnerability (CVE-2026-71362) in Adobe’s Commerce and Magento e-commerce platforms have been detected, doubtlessly permitting attackers to hijack buyer accounts.
The flaw is described as an incorrect authorization vulnerability that could possibly be leveraged to “acquire elevated entry to delicate sources” with out authentication and is likely one of the seven points that Adobe addressed in a safety replace yesterday.
Though the software program vendor states within the advisory that it isn’t conscious of exploits within the wild for any of the mounted flaws, eCommerce safety firm Sansec says that its Protect net utility firewall (WAF) is already blocking CVE-2026-71362 exploitation makes an attempt.
In accordance with Sansec, exploiting the vulnerability requires “no present account, administrator privileges or consumer interplay.”
After analyzing Adobe’s patch, the researchers pinned the issue to Magento improperly dealing with buyer id in an account session.
“Sansec reviewed the patch and confirmed that the vulnerability lets attackers swap a buyer session to a different buyer account. This provides them entry to the sufferer’s account and personal buyer knowledge,” the security company explains.
4 of the opposite flaws Adobe mounted with yesterday’s updates obtained a high-severity rating, and the opposite two are medium and low severity:
- CVE-2026-48414 (7.7, excessive severity): Saved cross-site scripting vulnerability that might lead to arbitrary code execution. Exploitation requires authentication and administrator privileges.
- CVE-2026-48413 (8.7, excessive severity): Saved cross-site scripting vulnerability that might lead to arbitrary code execution. It requires authentication however not administrator privileges.
- CVE-2026-48415 (7.6, excessive severity): Incorrect-authorization vulnerability affecting Adobe Commerce B2B that might allow a security-feature bypass. It requires authentication however not administrator privileges.
- CVE-2026-48416 (7.5, excessive severity): Incorrect-authorization vulnerability that might allow a security-feature bypass. It requires neither authentication nor administrator privileges.
- CVE-2026-48411 (6.5, medium severity): Incorrect-authorization vulnerability that might allow a security-feature bypass. Exploitation requires authentication and administrator privileges.
- CVE-2026-48412 (2.7, low severity): Incorrect-authorization vulnerability that might lead to privilege escalation. Exploitation requires authentication and administrator privileges.
Web site directors are suggested to use the August 2026 safety replace for at present supported Commerce, Commerce B2B, and Magento launch strains as quickly as attainable.
In accordance with Sansec, these month-to-month fixes are distributed as remoted patch information fairly than a brand new safety launch or up to date Composer packages.
Web site admins should first guarantee they’re working the most recent -p launch obtainable for his or her supported launch department earlier than making use of the corresponding remoted patch.
General prevention scores can cover what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses approach by approach throughout 338 million simulations run in buyer manufacturing environments.

