securityaffairs.com 8/13/2026, 6:26:38 PM · external

Adobe Commerce CVE-2026-71362 exploited, accounts hijacked

Adobe Commerce CVE-2026-71362 exploited, accounts hijacked
CyberSIXT Evidence Panel
Primary Source helpx.adobe.com
CISA KEV Not in KEV
Patch Patch Status Unknown

ADOBE Commerce's critical flaw, CVE-2026-71362, has come under attack shortly after its public disclosure, allowing unauthenticated attackers to hijack customer accounts and access sensitive data. Registered with a CVSS score of 9.1, the vulnerability affects multiple Adobe Commerce versions. Following the disclosure, cybersecurity firm Sansec reported blocking early exploitation attempts. Adobe has released patches that address this and other vulnerabilities, advising users to update their systems immediately. The exploit does not require prior account access or user interaction, heightening security concerns.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline