The first attempts to exploit are already underway CVE-2026-71362the critical vulnerability that Adobe patched in the August security update for Adobe Commerce And Magento. The issue is classified as incorrect authorization and, according to the bulletin, allows gain high access to sensitive resources without any authentication. The result is access to an online store’s customer accounts and the data they contain.
Patch analysis conducted by Sanseca company specializing in security for e-commerce, places the problem in the management of the customer’s identity within the session. “Sansec reviewed the patch and confirmed that the vulnerability allows attackers to switch a customer’s session to another customer account,” the researchers write, “thus gaining access to the victim’s account and the customer’s personal data.” Exploitation, they add, does not require a pre-existing account, administrator privileges or user interaction.
In the bulletin Adobe says it is not aware of any active exploitations for none of the flaws fixed, while Sansec claims that its Shield application firewall is already blocking attempts against CVE-2026-71362. The two positions are not mutually exclusive, because the telemetry of a WAF observes traffic that the software manufacturer has no way of seeing. For those who manage a shop the result does not change: the window between the publication of the correction and the first attempts has already closed.
The other six vulnerabilities in the update
The August package closes seven problems in total. Two are cross-site stored scripting that can lead to arbitrary code execution: CVE-2026-48413with a score of 8.7, requires authentication but not administrator privileges, while CVE-2026-48414at 7.7, requires both. They therefore assume that the attacker already has valid credentials on the installation.
The remaining four all fall into the same critical flaw category, incorrect authorization, with smaller impacts. CVE-2026-48416 (7.5) allows you to bypass a security feature and requires neither authentication nor administrative privileges; CVE-2026-48415 (7.6) produces the same effect on Adobe Commerce B2Bbut only by an authenticated user. They close the list CVE-2026-48411 (6.5), also a bypass, e CVE-2026-48412 (2.7), which leads to elevation of privilege: both require authentication and administrator privileges.
The update procedure
Adobe monthly fixes come distributed as isolated patch filesand not as a new security release or updated Composer packages. Those who administer the site must first verify that they are on the latest -p release available for their supported branch, and only then apply the corresponding patch. It is a two-stage intervention, which lengthens the exposure window just as the attempts are already circulating.
The update covers the currently supported lines of Adobe Commerce, Adobe Commerce B2B, and Magento. For CVE-2026-71362 the available sources do not report a CVSS score, other than the classification as critical. The recommendation for anyone managing an installation remains: apply the fix as soon as possible.

