๐จ ACTIVE EXPLOITATION
- Attackers exploit Adobe Commerce flaw to hijack customer accounts
CVE-2026-71362Attackers are exploiting a critical Adobe Commerce vulnerability to hijack customer accounts.- Adobe Commerce and Magento Open Source stores are affected.
- CVE-2026-71362 enables unauthenticated customer account takeover and access to private data.
- The flaw carries a CVSS score of 9.1 and requires no account, privileges, or user interaction.
- Attackers exploit improper customer identity handling to switch sessions to other accounts.
- Sansec has detected exploitation attempts and is blocking them with its Shield WAF. ๐ Source: helpx.adobe.com ยท ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ CVEs & KEV
- Other: 19 CVEs (worst 10.0)