Hackers began targeting a new Critical Severity Adobe Commerce vulnerability immediately after its public disclosure, web store security firm Sansec reports.
Tracked as CVE-2026-71362 (CVSS score of 9.1), the security flaw is described as an improper authorization issue that allows unauthorized attackers to elevate their privileges.
Adobe resolved the flaw on Tuesday for an August 2026 patch, saying there was no evidence of an exploit in the wild, but warned that threats had targeted Commerce before.
A bit behind that of Adobe consultative was published, Sansec warned that it had blocked the first exploit attempts targeting the CVE.
According to Sansec, the flaw could be used by remote, unauthenticated attackers to take over other customer accounts.
“Sansec has reviewed the patch and confirmed that the vulnerability allows attackers to switch a client session to another client account. This gives them access to the victim’s account and private client data,” the cybersecurity firm noted.
Adobe resolved the underlying issue by changing the way Commerce and Magento handle customer identity in account sessions, Sansek says.
The vulnerability affects all open source versions of Commerce, Commerce B2B, and Magento up to and including those running the July 2026 patches.
On Tuesday, Adobe released an isolated patch to fix the critical flaw and six other security flaws in all three products, and posted installation instructions.
“Please apply the latest security updates as soon as possible. Successful exploitation of these vulnerabilities could lead to arbitrary code execution, security bypass, and privilege escalation,” the company noted.
“(The isolated patch) allows merchants to apply the patch in isolation with less risk of delays due to potential integration issues,” Adobe said.
Related: WordPress 7.0.4 fixes a remote code execution vulnerability
Related: Nightmare Eclipse Removes Windows Zero-Day Exploit ‘ShieldBreak’
Related: Zoom fixes a zero-click code execution vulnerability
Related: SonicWall fixes critical vulnerabilities in the discontinued GMS platform