Skip to main content

Adobe Commerce and Magento Unauthenticated Customer Account Hijacking Now Under Active Exploitation (CVE-2026-71362)

Scope: Adobe Commerce and Magento Open Source (All Supported Versions Prior to August 2026 Security Update)

Severity: Red

Sansec confirmed that its Shield WAF is already blocking active exploitation attempts against CVE-2026-71362, a critical improper customer identity handling flaw in Adobe Commerce and Magento e-commerce platforms that requires no existing account, no administrator privileges, and no user interaction, allowing unauthenticated attackers to hijack any customer account on a vulnerable store by manipulating account session identifiers. Adobe Commerce and Magento power a significant portion of Ugandan e-commerce operations including online retail stores, payment portals, and B2B ordering platforms, making active exploitation a direct financial and reputational risk to any business running an online store. Website administrators must apply Adobe's August 2026 security update immediately by first ensuring they are running the latest patch release for their supported branch before applying the isolated monthly patch file.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.