discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Hackers exploit a critical vulnerability in Adobe's Commerce and Magento e-commerce platforms, potentially allowing them to hijack customer accounts. The flaw, described as an incorrect authorization vulnerability, could be leveraged to gain elevated access to sensitive r…

By Bill Toulas·Aug 12·bleepingcomputer.com·3 min read

Intelligence analysis by Llama

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Image: bleepingcomputer.com

A critical vulnerability in Adobe's Commerce and Magento e-commerce platforms has been detected, potentially allowing hackers to hijack customer accounts. The flaw, described as an incorrect authorization vulnerability, could be leveraged to gain elevated access to sensitive resources without authentication.

Why it matters

This story matters to someone following Security because it highlights a critical vulnerability in Adobe's Commerce and Magento e-commerce platforms that could be exploited by hackers to hijack customer accounts.

Imagine you have an online store where people can buy things from you. Hackers found a way to break into the system and take control of people's accounts, so they can buy things without paying for them. This is a big problem because it could let hackers steal people's money or personal information.

Analysis

Critical Vulnerability in Adobe Commerce and Magento E-commerce Platforms Detected

A critical vulnerability in Adobe's Commerce and Magento e-commerce platforms has been detected, potentially allowing hackers to hijack customer accounts. The flaw, described as an incorrect authorization vulnerability, could be leveraged to gain elevated access to sensitive resources without authentication.

According to Sansec, a security company that has been analyzing Adobe's patch, the vulnerability lets attackers switch a customer session to another customer account, giving them access to the victim's account and private customer data. This is a significant concern for e-commerce businesses that rely on Adobe's Commerce and Magento platforms.

The vulnerability, identified as CVE-2026-71362, is one of the seven issues that Adobe addressed in a security update yesterday. Although Adobe states that it is not aware of exploits in the wild for any of the fixed flaws, Sansec says that its Shield web application firewall (WAF) is already blocking CVE-2026-71362 exploitation attempts.

Sansec's analysis of Adobe's patch reveals that the vulnerability is caused by Magento improperly handling customer identity in an account session. This allows attackers to exploit the vulnerability without requiring any existing account, administrator privileges, or user interaction.

The implications of this vulnerability are significant, and e-commerce businesses that rely on Adobe's Commerce and Magento platforms should take immediate action to address the issue. This includes applying the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible.

Four Other Flaws Fixed in Adobe's Security Update

In addition to the critical vulnerability in Adobe's Commerce and Magento e-commerce platforms, Adobe's security update also addressed four other flaws. These flaws, identified as CVE-2026-48414, CVE-2026-48413, CVE-2026-48415, and CVE-2026-48416, received a high-severity score and could potentially be exploited by attackers.

CVE-2026-48414 is a stored cross-site scripting vulnerability that could result in arbitrary code execution. Exploitation requires authentication and administrator privileges.

CVE-2026-48413 is also a stored cross-site scripting vulnerability that could result in arbitrary code execution. It requires authentication but not administrator privileges.

CVE-2026-48415 is an incorrect-authorization vulnerability affecting Adobe Commerce B2B that could enable a security-feature bypass. It requires authentication but not administrator privileges.

CVE-2026-48416 is an incorrect-authorization vulnerability that could enable a security-feature bypass. It requires neither authentication nor administrator privileges.

Website Administrators Should Take Immediate Action

Website administrators are advised to apply the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible. This includes ensuring that they are running the latest -p release available for their supported release branch before applying the corresponding isolated patch.

Once attackers have valid credentials, only 37% of their actions are blocked. Overall prevention scores can hide what happens after initial access. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Key points

  • A critical vulnerability in Adobe's Commerce and Magento e-commerce platforms has been detected, potentially allowing hackers to hijack customer accounts.
  • The flaw, described as an incorrect authorization vulnerability, could be leveraged to gain elevated access to sensitive resources without authentication.
  • Website administrators are advised to apply the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible.
  • The vulnerability, identified as CVE-2026-71362, is one of the seven issues that Adobe addressed in a security update yesterday.
  • Sansec's analysis of Adobe's patch reveals that the vulnerability is caused by Magento improperly handling customer identity in an account session.
The Upside

If the vulnerability is patched quickly, e-commerce businesses can prevent hackers from exploiting it. This could help to prevent financial losses and protect customer data.

The Downside

If the vulnerability is not patched quickly, hackers could continue to exploit it, leading to financial losses and data breaches for e-commerce businesses.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityadobe-commercemagentovulnerabilityhijackcustomer-accounts

Author

Bill Toulas

Intelligence analysis by

Llama

Published

Aug 12, 2026

Source

bleepingcomputer.com

Share

Topics

securityadobe-commercemagentovulnerabilityhijackcustomer-accounts

Related

More from this desk

Aug 13·thehackernews.com

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Attackers have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040, which refers to a critical security feature bypass that stems from weak authentica…

Aug 12·bleepingcomputer.com

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

Researchers say a single IP is running an ongoing campaign that steals data exposed to guest users in Salesforce Experience Cloud and ServiceNow portals.

Aug 12·bleepingcomputer.com

Android Malware Combo Takes Out Loans and Relays Victims' Credit Cards

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time.

Aug 10·schneier.com

Python Now Has a Post-Quantum Encryption Library

Python's pyca/cryptography library now supports ML-KEM and ML-DSA, the NIST-standard post-quantum key-establishment and digital-signature primitives, available via pip.