bleeping-computer · Crawled Aug 12, 2026

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Read original article ↗

AI Summary

Hackers are actively exploiting a critical vulnerability, CVE-2026-71362, in Adobe Commerce and Magento platforms to hijack customer accounts without authentication or user interaction. The flaw stems from improper handling of customer identity in account sessions, allowing attackers to switch between customer accounts. Security firm Sansec has observed exploitation attempts in the wild and confirms that the vulnerability enables unauthorized access to private customer data. Adobe released patches as isolated updates, urging administrators to apply them immediately to mitigate risk.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.