Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Security researchers say hackers are attempting to exploit Adobe Commerce and Magento flaw CVE-2026-71362, an incorrect authorization issue that could let attackers switch customer sessions and access private data. Adobe issued an August 2026 security update and says it has not seen exploits in the wild. Sansec says its WAF blocks attempts and notes no auth or user interaction is needed.
How this was made
The 30-second read
Why it matters
Attackers may hijack customer accounts and access private data by switching a victim’s session to another account. Admins are advised to apply isolated patch files after confirming they are on the latest -p release for their supported branch, and WAFs may already be blocking attempts.
Market read
Traders should treat this as a near-term operational security catalyst for Adobe Commerce/Magento users, with potential reputational and support-cost implications for Adobe if exploitation scales.
What to watch
The article focuses on one CVE and patch mechanics; actual financial impact depends on how many sites are unpatched, whether credential stuffing is involved, and whether Adobe faces any customer churn or contractual penalties.
Background
Adobe addressed multiple Commerce and Magento vulnerabilities in an August 2026 security update, including CVE-2026-71362, described as an incorrect authorization issue enabling customer account session switching.
Ticker impact
Article says hackers are exploiting a critical Adobe Commerce and Magento flaw (CVE-2026-71362) to hijack customer accounts.
Likely limited direct impact on ADBE stock unless broader Adobe security or enterprise demand concerns emerge.
The article is a security advisory and patching guidance for Adobe Commerce/Magento, not an Adobe earnings or demand shock; however, account-hijack risk can pressure enterprise customers and support costs.
Market effects
Highlights ongoing risk in e-commerce platforms and the importance of WAF coverage and rapid isolated patch deployment.
No clear regional demand signal; likely global patching and security operations response.
Cross-border e-commerce sites using Magento/Adobe Commerce may face coordinated incident response and compliance scrutiny.
Counterpoint
Adobe states it is not aware of exploits in the wild for the fixed flaws, and a WAF vendor reports blocking attempts, which may limit realized damage.
Key entities
- software platformAdobe Commerce and Magento
E-commerce platforms affected by CVE-2026-71362 and other vulnerabilities fixed in the August 2026 security update.
- vulnerabilityCVE-2026-71362
Incorrect authorization vulnerability that could allow attackers to gain elevated access without authentication and switch customer sessions.
- security companySansec
Says its Shield WAF is blocking exploitation attempts and reviewed the patch to confirm session-switching behavior.



