THE article reports on a recent critical-severity vulnerability in Adobe Commerce, tracked as CVE-2026-71362, which has a CVSS score of 9.1. The flaw, described as an incorrect authorization issue, allows unauthenticated attackers to elevate privileges and take over customer accounts. This vulnerability was publicly disclosed by Adobe and quickly targeted by hackers, prompting immediate action from webstore security firm Sansec, which reported blocking exploitation attempts.
Adobe released a patch to fix this issue and six other vulnerabilities, emphasizing the need for users to apply updates promptly to prevent potential exploitation. The flaw affects multiple versions of Adobe Commerce, including Commerce B2B and Magento Open Source.