Summary
Attackers began probing CVE-2026-71362 (CVSS 9.1), a critical incorrect-authorization flaw in Adobe Commerce, B2B, and Magento Open Source almost immediately after Adobe's August 11 patch (APSB26-92) went public. Sansec blocked the first exploitation attempts shortly after the advisory.
Take Action:
If you run Adobe Commerce, Adobe Commerce B2B or Magento Open Source, update immediately to the "-2026-aug" release for your version. Attackers are already exploiting this flaw to take over customer accounts. After patching, force a logout of all active customer sessions and review recent account activity for signs that someone else accessed customer data.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)