Adobe patched a critical unauthenticated session-hijacking flaw in Adobe Commerce and Magento in its August 2026 security update. CVE-2026-71362, rated CVSS 9.1, allows an attacker with no account and no privileges to take over any customer session on an affected storefront. Exploitation started within hours of Adobe’s disclosure — Sansec Shield WAF was already blocking active attempts by August 12. If you run an Adobe Commerce or Magento store and haven’t applied the August 2026 patch, your customers’ accounts are at risk right now.
What the Vulnerability Is
CVE-2026-71362 is an incorrect-authorization (CWE-863) vulnerability in the way Adobe Commerce and Magento handle customer identity during an active session. The flaw allows an unauthenticated remote attacker to switch a live session context to another customer’s account — effectively stealing any logged-in user’s session without knowing their password.
No authentication is required. No admin access is required. No user interaction from the victim is required. An attacker on the open internet who knows a target store’s URL can manipulate the session identity logic, pivot into another customer’s account, and view saved addresses, order history, stored payment method references, and any other account data.
Adobe’s August 2026 advisory (APSB26-92) disclosed four vulnerabilities in the same batch. The most dangerous by CVSS score is CVE-2026-71362 (9.1). The others in the advisory include:
- CVE-2026-48413 — stored cross-site scripting (CVSS 8.7)
- CVE-2026-48414 — stored cross-site scripting (CVSS 7.7)
- CVE-2026-48415 — B2B authenticated authorization bypass (CVSS 7.6)
- CVE-2026-48416 — unauthenticated authentication bypass (CVSS 7.5)
Patches are distributed as isolated patch files rather than a full new release. Adobe’s instructions specify that the store must be running the latest -p (patch-level) release before the isolated patch can be applied cleanly.
Why It Matters
- No authentication barrier. Most web vulnerabilities require at least a low-privilege account. CVE-2026-71362 requires nothing — any visitor to your store could exploit it.
- Active exploitation already underway. Security firm Sansec had its WAF blocking real-world exploitation attempts on August 12, 2026 — the same day Adobe published the advisory. There is no grace period to wait and see.
- Customer data exposure. A hijacked session gives an attacker full access to that customer’s order history, saved addresses, stored payment tokens, loyalty points, and any profile data. In B2B deployments this can also expose contract pricing and purchase order history.
- Regulatory exposure. Unauthorized access to customer PII and payment data implicates PCI DSS, GDPR, and CCPA depending on your geography. An unpatched breach is a compliance event, not just a security event.
- Magento Open Source is also affected. This isn’t limited to the enterprise Adobe Commerce product — if you self-host Magento Open Source, you are in scope.
Am I Affected?
- You run Adobe Commerce or Magento Open Source on any currently-supported version branch that has not received the August 2026 security patch.
- The patch was released August 12, 2026. If you haven’t applied it, assume you are vulnerable.
- Adobe Commerce on Cloud customers: verify patch delivery with your Adobe Cloud dashboard — automated rollout timing varies.
- Merchants running end-of-life Magento versions (anything before the 2.4.x branch on a supported sub-release) are also vulnerable and have no supported patch path — upgrade is required.
- You are not directly affected if you use Shopify, WooCommerce, or another platform — this flaw is specific to the Adobe Commerce / Magento codebase.
What to Do About It: Step-by-Step
Step 1: Identify your current version
# In your Magento root directory:
php bin/magento --version
# Or check Admin → System → System Information
Step 2: Confirm you’re on the latest -p release before patching
Adobe’s isolated patches require the latest patch-level release as a base. If you’re on 2.4.7-p4, for example, you must be on that specific sub-release before applying the isolated patch for APSB26-92. Check Adobe’s release notes to confirm your -p level is current before proceeding.
Step 3: Apply the APSB26-92 isolated patch
Adobe distributes the fix as an isolated patch file. Download it from the Adobe Security Bulletin page for APSB26-92 and apply it per Adobe’s instructions for your version branch:
# Using Composer (typical managed installs):
composer require magento/security-patch-apsb26-92
# Or apply the downloaded patch file manually:
git apply APSB26-92-2.4.x.patch
Follow Adobe’s exact instructions for your version — the process differs slightly between versions. After applying, run bin/magento setup:upgrade and clear caches.
Step 4: Clear caches and verify
php bin/magento cache:flush
php bin/magento cache:clean
Then verify the patch is applied by checking php bin/magento --version or running php bin/magento security:check if your version supports it.
Step 5: Apply WAF rules as interim protection (if patching takes time)
If your store is behind a WAF (Cloudflare, Fastly, Sucuri, etc.), apply any available Magento/Adobe Commerce virtual patches for APSB26-92. Sansec published WAF signatures on August 12. This buys time but is not a substitute for patching.
Step 6: Audit session logs for signs of exploitation
Review your application and NGINX/Apache access logs for anomalous session behavior: rapid switching of customer_id within a single session token, unusual account access from unexpected geolocations, or bulk enumeration of account-related endpoints.
Step 7: Review the other APSB26-92 CVEs
The August patch addresses four vulnerabilities. Even if CVE-2026-71362 is your primary concern, the XSS flaws (CVE-2026-48413, -48414) and auth bypasses (-48415, -48416) should also be closed. The isolated patch covers all of them.
Quick-Win Checklist
- Identify your current Magento/Adobe Commerce version and -p patch level.
- Ensure you’re on the latest -p release before applying the isolated patch.
- Download and apply the APSB26-92 isolated patch from Adobe.
- Run
setup:upgradeand flush caches after patching. - Activate WAF virtual patches as an interim measure if the patch takes time to deploy.
- Review access logs for anomalous session activity (session identity switching, bulk account access).
- If on end-of-life Magento, escalate to an upgrade — there is no safe workaround for unsupported versions.
Sources
- BleepingComputer — Hackers exploit critical Adobe Commerce flaw to hijack customer accounts (August 12, 2026)
- The Hacker News — Adobe patches CVEs including August 2026 security bulletin (August 12, 2026)
- Adobe Security Bulletin APSB26-92
DALL-E Image Prompt
8-bit pixel-art scene: a shadowy figure at a terminal reaching into an e-commerce shopping cart icon and swapping two glowing customer account cards while a padlock icon flickers red. Server rack in the background with blinking orange warning lights. Dark neon-green color scheme on a black background.