Published Security3 min read
Adobe Commerce session-switching flaw drew attack traffic almost immediately after disclosure
CVE-2026-71362 lets an unauthenticated attacker move a session onto someone else's customer account.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Hackers began targeting CVE-2026-71362, a critical Adobe Commerce flaw with a CVSS score of 9.1, shortly after its public disclosure.
- The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data.
- The flaw affects Adobe Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches.
- Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory.
- Sansec's advisory states: "Adobe has released APSB26-92 as isolated patch files."
Compiled by The WatchSomething wrong?How this is made
Why it matters
Adobe published APSB26-92 as isolated patch files covering seven vulnerabilities in Commerce and Magento, including an unauthenticated customer account takeover rated CVSS 9.1 [5][7]. According to Sansec, attackers began probing for that bug, CVE-2026-71362, shortly after the advisory went public, and the firm blocked the first exploitation attempts it saw [1][4].
The mechanics are unglamorous and that is the problem. Sansec says it reviewed Adobe's patch and confirmed the flaw lets an attacker switch a customer session onto another customer's account, handing over that account and the private customer data in it [8]. No existing account, no administrator privileges, no user interaction, per Sansec [9]. Adobe's fix changes how Magento handles customer identity in account sessions [11]. The other issues in the same advisory include stored cross-site scripting and authorization problems [12], which is to say six further reasons to apply the update [13].
The affected footprint is wide: Commerce, Commerce B2B and Magento Open Source through the July 2026 patches [3]. Adobe released the fix on its own and told customers to install it [6].
Two things about this deserve attention from anyone running a storefront. First, the disclosure-to-exploitation gap. The advisory itself was the trigger; the attack traffic followed the publication, not some slow independent discovery [1][4]. That is the normal pattern for Magento now, and it makes the common practice of batching e-commerce patching into a monthly or quarterly maintenance window a bet that no one is reading Adobe's advisories faster than you are. Isolated patch files exist precisely because the fix is not meant to wait for the next scheduled release [5].
Second, the detection problem. An account takeover that works by switching a session to another customer looks, in logs, like a customer using their own account [8]. There is no failed login to alert on, no privilege escalation to an admin role, no obvious anomaly for a WAF rule tuned to injection payloads. If exploitation happened before you patched, the evidence will be in session and order-history activity, not in your authentication failures. Sansec's own commercial product, Sansec Shield, is described by the company as already blocking exploitation attempts [10]; that is a vendor statement about a vendor product, and it is not a substitute for having applied Adobe's patch.
For teams triaging: confirm your version against the July 2026 baseline [3], apply APSB26-92 [5], then treat the interval between the advisory's publication and your patch as a period requiring review rather than assumed safety.
What to watch: whether Adobe or Sansec publishes indicators of compromise or observed exploitation volume for CVE-2026-71362, and whether the session-switching primitive gets folded into the automated skimmer toolkits that have historically followed Magento account-takeover bugs. Also watch for the gap between the isolated patch and hosted or managed Magento providers rolling it out for their tenants, since that decision is often not the merchant's to make.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Hackers began targeting CVE-2026-71362, a critical Adobe Commerce flaw with a CVSS score of 9.1, shortly after its public disclosure.
- [2]
The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data.
ReportedView cited source - [3]
The flaw affects Adobe Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches.
ReportedView cited source - [4]
Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory.
- [5]
Sansec's advisory states: "Adobe has released APSB26-92 as isolated patch files."
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityaffairs.comPierluigi PaganiniAug 13Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure
Additional citations
- SecurityAffairs, reporting on Sansec advisory
- Sansec
- Sansec advisory, quoted by SecurityAffairs
- Sansec advisory



