View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Attackers exploit Adobe Commerce flaw to hijack customer accounts

๐Ÿšจ ACTIVE EXPLOITATION

  • Attackers exploit Adobe Commerce flaw to hijack customer accounts CVE-2026-71362 Attackers are exploiting a critical Adobe Commerce vulnerability to hijack customer accounts.
    • Adobe Commerce and Magento Open Source stores are affected.
    • CVE-2026-71362 enables unauthenticated customer account takeover and access to private data.
    • The flaw carries a CVSS score of 9.1 and requires no account, privileges, or user interaction.
    • Attackers exploit improper customer identity handling to switch sessions to other accounts.
    • Sansec has detected exploitation attempts and is blocking them with its Shield WAF. ๐Ÿ“„ Source: helpx.adobe.com ยท ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ”“ CVEs & KEV

  • Other: 19 CVEs (worst 10.0)

๐Ÿ“‹ ADVISORIES

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check