Attackers Exploiting Critical Adobe Commerce Flaw
Active exploitation of CVE-2026-71362 targets Adobe Commerce and Magento storefronts. CVSS 9.1 critical flaw enables account hijacking without user interaction.
Active exploitation confirmed. Attackers are targeting CVE-2026-71362 in Adobe Commerce and Magento Open Source to hijack customer accounts on live storefronts. CVSS 9.1, critical. No user interaction required.
Observed activity
BleepingComputer reports confirmed exploitation attempts against live Adobe Commerce and Magento deployments. Attackers are leveraging the incorrect authorization flaw to gain elevated access to customer accounts. Adobe published the CVE on August 11 — confirmed attacks followed within 24 hours of public disclosure.
Per NVD: the flaw is an incorrect authorization issue that permits privilege escalation to sensitive resources without user interaction.
Patch
Available. Adobe released the fix alongside disclosure. No workaround has been published — patching is the remediation path. Check affected version ranges at Adobe’s security bulletins.
KEV status
Not confirmed on the CISA Known Exploited Vulnerabilities catalog as of August 12, 2026. CVSS 9.1 plus confirmed active exploitation is the typical profile for KEV addition. Monitor the KEV tracker.
What to do
Apply the available patch immediately. Adobe Commerce and Magento power a significant share of global e-commerce storefronts — the attack surface is wide, and customer PII, session data, and order history are in scope.
Review access logs for unauthorized account access or privilege escalation patterns and cross-reference against August 11–12 timelines.
Running a vulnerable storefront with customer data in scope after this disclosure — that’s a choice, not a gap. The patch is out.
- [ CRITICAL ] CVE-2026-71362 Incorrect Authorization in Adobe Commerce and Magento Open Source
Found this useful? Share it.


