ADOBE Commerce's critical flaw, CVE-2026-71362, has come under attack shortly after its public disclosure, allowing unauthenticated attackers to hijack customer accounts and access sensitive data. Registered with a CVSS score of 9.1, the vulnerability affects multiple Adobe Commerce versions. Following the disclosure, cybersecurity firm Sansec reported blocking early exploitation attempts. Adobe has released patches that address this and other vulnerabilities, advising users to update their systems immediately. The exploit does not require prior account access or user interaction, heightening security concerns.
Adobe Commerce CVE-2026-71362 exploited, accounts hijacked
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
CISA Flags Critical WSO2 and Magento Flaws Used in Attacks
securityaffairs.com
-
CISA Warns of Exploited WSO2 and Adobe Commerce Flaws
securityonline.info
-
CISA Flags Actively Exploited Critical Flaw in Adobe Commerce
cisa.gov
-
CVE-2026-71362 Exploited: Adobe Commerce Account Takeover, Details and PoC are Public
securityonline.info
-
Adobe Commerce CVE-2026-71362 exploited, accounts hijacked
securityaffairs.com
-
Adobe Commerce flaw CVE-2026-71362 lets attackers hijack accounts
securityweek.com