Adobe Commerce e Magento sotto attacco: sfruttata CVE-2026-71362
Vulnerabilities

Illustrative image generated with AI

Adobe Commerce and Magento Under Attack: CVE-2026-71362 Exploited

Critical CVE-2026-71362 exploit attempts target Adobe Commerce and Magento. Learn about the flaw and security update for admins.

Text generated by artificial intelligence, published without human review. AI transparency

Attempts to Exploit a Critical Flaw Detected

On August 12, 2026, attempts to exploit CVE-2026-71362, a critical vulnerability in Adobe Commerce and Magento, were detected.

The flaw involves an authorization error that could allow an unauthenticated attacker to access sensitive resources and compromise customer accounts. No existing account, administrative privileges, or user interaction are required.

Sansec stated that its Shield WAF is blocking the observed attempts. Adobe, however, says it is not aware of active exploitation of the vulnerabilities addressed by the update. At this time, there is no indication that the detected attacks resulted in successful compromises.

How the Customer Session Attack Works

Patch analysis indicates improper handling of customer identity within the session. An attacker may attempt to associate their own session with another customer’s account, gaining access to the associated profile and private data.

The issue is particularly significant for online stores, as a successful attack could expose personal information and provide access to accounts without legitimate authentication.

The exact affected versions have not been disclosed. Supported lines of Adobe Commerce, Adobe Commerce B2B, and Magento are affected.

The Seven Vulnerabilities Addressed

The August 2026 security update addresses seven issues:

Identifier Severity Impact and Requirements
CVE-2026-71362 Critical Improper authorization, unauthenticated access to sensitive resources, and potential compromise of customer accounts.
CVE-2026-48414 High, CVSS 7.7 Persistent XSS with potential arbitrary code execution; requires authentication and administrative privileges.
CVE-2026-48413 High, CVSS 8.7 Persistent XSS and potential arbitrary code execution; requires authentication but not administrative privileges.
CVE-2026-48415 High, CVSS 7.6 Improper authorization in Adobe Commerce B2B; requires authentication but not administrative privileges.
CVE-2026-48416 High, CVSS 7.5 Improper authorization and potential security feature bypass; does not require authentication.
CVE-2026-48411 Medium, CVSS 6.5 Improper authorization and potential security feature bypass; requires authentication and administrative privileges.
CVE-2026-48412 Low, CVSS 2.7 Improper authorization with potential privilege escalation; requires authentication and administrative privileges.

What Administrators Should Do

Operators should promptly apply the August 2026 security update to supported Commerce, Commerce B2B, and Magento releases.

The fixes are distributed as isolated patches, not as a new security release or updated Composer packages. Before installation, verify that the environment is running the latest available “-p” release for the supported branch.

Organizations should also maintain or implement WAF rules capable of blocking attempts associated with CVE-2026-71362. Sansec Shield is already applying this type of protection. They should additionally review authentication and customer-account access logs, focusing on anomalous session associations and access that cannot be attributed to legitimate users.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsAdobe CommerceMagentoCVE-2026-71362security vulnerabilitye-commerce securityauthorization flawsecurity patchMagento update
Back to home