
A critical vulnerability in Adobe Commerce and Magento Open Source — tracked as CVE-2026-71362 — is already being actively exploited. The flaw is an incorrect authorization bug that lets attackers gain elevated access to sensitive resources with no existing account, no administrator privileges, and no user interaction required. Researchers at Sansec traced the issue to Magento improperly handling customer identity in an account session, meaning an attacker can impersonate any registered customer and take over their account.
Adobe shipped a fix in its August 2026 security update, which also addresses four high-severity flaws and two lower-severity issues across Commerce, Commerce B2B, and Magento. Because the patch is distributed as an isolated patch file rather than a full release, store owners must first verify they are on the latest -p release for their branch before applying it. Delaying is not an option: Sansec detected exploitation attempts immediately after Adobe’s disclosure.
How to check if you’re affected
Affected versions include all currently supported Adobe Commerce and Magento Open Source release lines. Log into the Adobe Commerce admin panel and check your installed version against the August 2026 security bulletin. Apply the corresponding isolated patch file for your release branch as soon as possible. Commerce B2B installations should treat CVE-2026-48415 (CVSS 7.6) as an additional priority.
