Exploitation attempts against a critical Adobe Commerce vulnerability began almost immediately after Adobe published its advisory, according to e-commerce security firm Sansec, which said it blocked the first attacks.
The flaw, tracked as CVE-2026-71362 with a CVSS score of 9.1, lets unauthenticated attackers switch a customer session to another customer’s account, hijacking the account and exposing private customer data. Sansec’s review of the patch confirmed the session-switching mechanism, and noted the exploit requires no existing account, no administrator privileges, and no user interaction.
Adobe released the fix as isolated patch files under advisory APSB26-92, covering Commerce, Commerce B2B, and Magento Open Source versions up to the July 2026 updates. The update addresses seven vulnerabilities in total, with the account takeover the most severe. The remaining flaws include stored cross-site scripting and authorization issues in how Magento handles customer identity in account sessions.
Sansec’s Shield product already blocks exploitation attempts, and the firm is urging merchants to apply the patch immediately. Attackers moving within hours of public disclosure has become the norm for high-value e-commerce targets, where a single account takeover can expose order history, addresses, and payment-related details stored in the customer profile.
Adobe has not reported mass exploitation in the wild at this stage, but the early probe activity is a strong signal that merchants running exposed Commerce and Magento instances should treat this as urgent. The advisory is part of Adobe’s regular security release cycle, and the isolated patch format means store owners need to apply it through their standard deployment process rather than waiting for a bundled release.
