Find notable cyber news and cases, enriched with sources, timelines, and signals.

Adobe Commerce and Magento incorrect authorization flaw (CVE-2026-71362, exploitation attempts detected)

Vulnerability
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-71362 exploitation attempts against Adobe Commerce and Magento are now being blocked, creating customer-account hijack and private-data exposure risk for affected storefronts. The flaw is an incorrect authorization issue that can let an attacker switch one customer session to another account without authentication. Sansec Shield WAF is already stopping observed abuse attempts while administrators are being urged to patch.

Related Happenings

Magento Open Source and Adobe Commerce PolyShell unauthenticated RCE flaw

Vulnerability
H score30 First: 19.03.2026 22:01 Last: 19.03.2026 22:01 Sources 1

About this happening: PolyShell is a Magento Open Source and Adobe Commerce vulnerability that can enable unauthenticated code execution and account takeover across stable version...

CISA KEV mitigation for BeyondTrust CVE-2026-1731

Advisory/Mitigation
H score46 First: 20.02.2026 19:02 Last: 20.02.2026 19:02 Sources 1

About this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...

CISA updates KEV entry for CVE-2026-1731

Public Sector Action
H score36 First: 20.02.2026 17:45 Last: 20.02.2026 17:45 Sources 1

About this happening: CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...

Timeline

  1. 12.08.2026 23:54 1 articles · 2h ago

    Adobe patches CVE-2026-71362 in Commerce and Magento

    Mitigation Patch Update

    Adobe's August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines addressed seven flaws, including CVE-2026-71362. Administrators were told to apply the corresponding isolated patch after first ensuring they are on the latest -p release for their supported branch.

    Show sources
  2. 12.08.2026 23:54 2 articles · 2h ago

    Sansec blocks CVE-2026-71362 exploitation attempts

    Initial Disclosure

    Sansec said its Shield WAF was already blocking CVE-2026-71362 exploitation attempts against Adobe Commerce and Magento. The incorrect-authorization flaw can let an attacker switch a customer session to another account without authentication, administrator privileges, or user interaction, creating risk of customer-account hijacking and access to private customer data.

    Show sources