By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: Session swap bug in Adobe Commerce draws attacks right after patch
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

Session swap bug in Adobe Commerce draws attacks right after patch

Sansec blocked the first exploits of CVE-2026-71362, an unauthenticated account takeover in Adobe Commerce rated 9.1.

CSBadmin
Last updated: August 14, 2026 1:48 pm
CSBadmin
2 Min Read
Share
SHARE

Exploitation attempts against a critical Adobe Commerce vulnerability began almost immediately after Adobe published its advisory, according to e-commerce security firm Sansec, which said it blocked the first attacks.

The flaw, tracked as CVE-2026-71362 with a CVSS score of 9.1, lets unauthenticated attackers switch a customer session to another customer’s account, hijacking the account and exposing private customer data. Sansec’s review of the patch confirmed the session-switching mechanism, and noted the exploit requires no existing account, no administrator privileges, and no user interaction.

Adobe released the fix as isolated patch files under advisory APSB26-92, covering Commerce, Commerce B2B, and Magento Open Source versions up to the July 2026 updates. The update addresses seven vulnerabilities in total, with the account takeover the most severe. The remaining flaws include stored cross-site scripting and authorization issues in how Magento handles customer identity in account sessions.

Sansec’s Shield product already blocks exploitation attempts, and the firm is urging merchants to apply the patch immediately. Attackers moving within hours of public disclosure has become the norm for high-value e-commerce targets, where a single account takeover can expose order history, addresses, and payment-related details stored in the customer profile.

Adobe has not reported mass exploitation in the wild at this stage, but the early probe activity is a strong signal that merchants running exposed Commerce and Magento instances should treat this as urgent. The advisory is part of Adobe’s regular security release cycle, and the isolated patch format means store owners need to apply it through their standard deployment process rather than waiting for a bundled release.

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverAdobe CommerceCVE-2026-71362MagentoSansec
SOURCES:Security AffairsSecurityWeek
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Dark web vendors peddle AI attack planners with nation-state depth
Next Article Akira’s Safe Mode play blinds EDR but crashes its own encryptor

Trending

Rydox marketplace owner pleads guilty and faces up to 20 years
Rydox marketplace owner pleads guilty and faces up to 20 years
September 28, 2026
Asus tells eShop shoppers an intruder reached their order records
Asus tells eShop shoppers an intruder reached their order records
September 28, 2026
Forgotten service accounts cracked open 28 Microsoft 365 tenants
Forgotten service accounts cracked open 28 Microsoft 365 tenants
September 28, 2026
Anyone holding your GitLab issue email can commit code as you
Anyone holding your GitLab issue email can commit code as you
September 28, 2026
Lunex stealer blinds endpoint defenses with a vulnerable AMD driver
Lunex stealer blinds endpoint defenses with a vulnerable AMD driver
September 28, 2026

Related Stories

CSBadmin

Click Studios Patches High-Severity Authentication Bypass in Passwordstate

Chained crystalline brain beneath a mechanical claw in a dark hall, monochrome green illustration
CSBadmin

AI models become ransom bait as thieves threaten to leak them

CSBadmin

Funds drained from six chains before Cosmos fix landed

CSBadmin

Zimbra Classic Web Client Vulnerability Allows Code Execution via Malicious Emails

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.