Adobe Commerce and Magento incorrect authorization flaw (CVE-2026-71362, exploitation attempts detected)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-71362 exploitation attempts against Adobe Commerce and Magento are now being blocked, creating customer-account hijack and private-data exposure risk for affected storefronts. The flaw is an incorrect authorization issue that can let an attacker switch one customer session to another account without authentication. Sansec Shield WAF is already stopping observed abuse attempts while administrators are being urged to patch.
Related Happenings
Magento Open Source and Adobe Commerce PolyShell unauthenticated RCE flaw
Vulnerability
H score30
First: 19.03.2026 22:01
Last: 19.03.2026 22:01
Sources 1
About this happening:
PolyShell is a Magento Open Source and Adobe Commerce vulnerability that can enable unauthenticated code execution and account takeover across stable version...
Magento Open Source and Adobe Commerce PolyShell unauthenticated RCE flaw
VulnerabilityAbout this happening: PolyShell is a Magento Open Source and Adobe Commerce vulnerability that can enable unauthenticated code execution and account takeover across stable version...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/Mitigation
H score46
First: 20.02.2026 19:02
Last: 20.02.2026 19:02
Sources 1
About this happening:
CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/MitigationAbout this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA updates KEV entry for CVE-2026-1731
Public Sector Action
H score36
First: 20.02.2026 17:45
Last: 20.02.2026 17:45
Sources 1
About this happening:
CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
CISA updates KEV entry for CVE-2026-1731
Public Sector ActionAbout this happening: CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
Timeline
-
12.08.2026 23:54 1 articles · 2h ago
Adobe patches CVE-2026-71362 in Commerce and Magento
Mitigation Patch UpdateAdobe's August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines addressed seven flaws, including CVE-2026-71362. Administrators were told to apply the corresponding isolated patch after first ensuring they are on the latest -p release for their supported branch.
Show sources
- Hackers exploit critical Adobe Commerce flaw to hijack customer accounts — www.bleepingcomputer.com — 12.08.2026 23:54
-
12.08.2026 23:54 2 articles · 2h ago
Sansec blocks CVE-2026-71362 exploitation attempts
Initial DisclosureSansec said its Shield WAF was already blocking CVE-2026-71362 exploitation attempts against Adobe Commerce and Magento. The incorrect-authorization flaw can let an attacker switch a customer session to another account without authentication, administrator privileges, or user interaction, creating risk of customer-account hijacking and access to private customer data.
Show sources
- Hackers exploit critical Adobe Commerce flaw to hijack customer accounts — www.bleepingcomputer.com — 12.08.2026 23:54
- Hackers exploit critical Adobe Commerce flaw to hijack customer accounts — www.bleepingcomputer.com — 12.08.2026 23:54