Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Adobe Commerce CVE-2026-71362: A Critical Vulnerability Exposed to Hackers Shortly After Public Disclosure


Adobe Commerce CVE-2026-71362: A critical vulnerability was exposed to hackers shortly after its public disclosure, allowing attackers to hijack customer accounts and access private data. The company has released an isolated fix and urges users to patch their systems as soon as possible.

  • Adobe Commerce has been affected by a critical vulnerability known as CVE-2026-71362.
  • Hackers began targeting this vulnerability soon after Adobe released its advisory, and cybersecurity firm Sansec blocked the first exploitation attempts.
  • The vulnerability affects Commerce, Commerce B2B, and Magento Open Source versions up until the July 2026 patches.
  • Sansec confirmed that the vulnerability lets attackers switch a customer session to another customer account, allowing unauthorized access to private data.
  • Acc attackers can exploit this flaw without existing account, administrator privileges, or user interaction.
  • Other notable security incidents include SharePoint CVE-2026-55040 and a Windows zero-day exploited by the North Korean Lazarus Group in Operation Dream Job.


  • Adobe Commerce, a popular e-commerce platform used by numerous businesses worldwide, has recently been affected by a critical vulnerability known as CVE-2026-71362. This flaw, which allows unauthenticated attackers to hijack customer accounts and access private data, was discovered shortly after its public disclosure in July 2026.

    According to reports, hackers began targeting this vulnerability soon after Adobe released its advisory outlining the issue. Cybersecurity firm Sansec promptly blocked the first exploitation attempts, but it is clear that the threat is still very much present.

    The vulnerability in question affects Commerce, Commerce B2B, and Magento Open Source versions up until the July 2026 patches. Adobe has since released an isolated fix for the problem and urges users to patch their systems as soon as possible to prevent unauthorized access.

    Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim's account and private customer data. Furthermore, attackers can exploit this flaw without existing account, administrator privileges, or user interaction.

    In addition to the Adobe Commerce issue, there have been several other notable security incidents in recent days. For example, SharePoint CVE-2026-55040 has come under attack following its public disclosure, while North Korean Lazarus Group has utilized a Windows zero-day in an operation known as Operation Dream Job.

    The impact of these vulnerabilities and attacks cannot be overstated, highlighting the importance of keeping one's systems up-to-date with the latest security patches. Furthermore, it serves as a reminder that hackers will always seek to exploit weaknesses in software and hardware, and vigilance is essential for protecting against such threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Adobe-Commerce-CVE-2026-71362-A-Critical-Vulnerability-Exposed-to-Hackers-Shortly-After-Public-Disclosure-ehn.shtml

  • https://securityaffairs.com/197149/hacking/adobe-commerce-cve-2026-71362-comes-under-attack-shortly-after-public-disclosure.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-71362

  • https://www.cvedetails.com/cve/CVE-2026-71362/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-55040

  • https://www.cvedetails.com/cve/CVE-2026-55040/


  • Published: Thu Aug 13 13:32:04 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us