
ADOBE Commerce is under active attack after the public disclosure of a critical vulnerability tracked as CVE-2026-71362. The flaw allows unauthenticated actors to hijack customer accounts and access sensitive store data.
The vulnerability carries a CVSS score of 9.1 and stems from an incorrect authorization check. It affects multiple releases of Adobe Commerce, including the B2B variant and Magento Open Source.
Adobe published details in advisory APSB26-92, noting that exploitation requires no prior authentication or user interaction. The advisory also patches six additional issues alongside this flaw. Security researchers at Sansec observed early exploit attempts and reported blocking them in real time.
Reports from securityaffairs.com and securityweek.com confirm that attackers began probing for the flaw within hours of disclosure. No specific threat actor group has been linked to the activity so far. The speed of the abuse highlights the need for rapid response.
Although no specific threat actors have been named, the rapid emergence of exploit attempts highlights the risk to online retailers that rely on the platform. Administrators are urged to treat the issue as a priority.
Defenders should apply the patches supplied in the advisory immediately, review access logs for anomalous login attempts, and consider implementing temporary web‑application‑firewall rules to block suspicious requests while updates are rolled out. Additionally, enabling multi‑factor authentication for admin accounts can reduce the impact of any compromised credentials. Continuous monitoring of system behaviour is recommended to detect any lingering threats.