Affected Systems
Adobe Commerce and Magento Open Source e-commerce platforms, all currently supported release lines. The vulnerability affects customer account session handling and requires no authentication to exploit.
Exploitation Status
Active exploitation confirmed. Sansec Shield WAF is blocking live exploitation attempts. The flaw allows attackers to switch customer sessions to other accounts without authentication, administrator privileges, or user interaction.
Business Impact
Attackers can hijack customer accounts and access private customer data including payment information, order history, and personal details. This poses direct financial and reputational risk to online retailers. Adobe claims no awareness of exploitation, but third-party security vendor Sansec reports active attacks. The vulnerability stems from improper customer identity handling in account sessions.
Urgency
🔴 Immediate
Recommended Actions
- Apply Adobe's August 2026 security update immediately for all Commerce, Commerce B2B, and Magento installations
- Verify you are running the latest -p release for your supported branch before applying the isolated patch file
- Monitor customer account activity logs for unusual session behavior or unauthorized account access
- Deploy or configure WAF rules to block CVE-2026-71362 exploitation attempts if patching cannot be completed immediately
- Review recent customer account access logs for indicators of compromise and notify affected customers if suspicious activity is detected
