A critical vulnerability in Adobe Commerce (CVE-2026-71362) has been detected, allowing unauthenticated account takeover with a CVSS score of 9.1. This flaw enables attackers to hijack customer accounts and access sensitive information like personal data and payment tokens. The vulnerability affects various Adobe Commerce versions and has been actively exploited since its public disclosure. Users are urged to update to the patched versions released in August 2026 and maintain security by employing additional web application firewall rules.
CVE-2026-71362 Exploited: Adobe Commerce Account Takeover, Details and PoC are Public
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline