Adobe Commerce CVE-2026-71362 Session Hijack Attempts Detected Within Hours of Disclosure
Attackers exploited CVE-2026-71362 immediately after disclosure, enabling unauthenticated account takeovers in Adobe Commerce. Sansec data contradicts Adobe's no-exploitation claim and reveals systemic patch delays among merchants. Rapid exploitation reinforces the need for enforced rapid patching in critical e-commerce platforms.
The flaw stems from improper customer identity validation in session handling across Adobe Commerce, Commerce B2B, and Magento Open Source. Attackers could swap session tokens to impersonate other accounts without authentication. Sansec confirmed the vector by reviewing the isolated patch Adobe shipped on Patch Tuesday, which altered session identity checks. All versions through the July 2026 updates remain exposed until the isolated fix is applied.
Adobe stated it saw no prior exploitation yet warned of historical targeting of Commerce instances. This internal inconsistency highlights the gap between vendor telemetry and third-party webstore monitoring. Rapid post-disclosure activity mirrors patterns seen in prior critical Adobe and Magento flaws where public patches immediately supplied weaponizable details to opportunistic actors.
Merchants running Adobe Commerce face elevated account takeover risk, particularly those with delayed patching cycles due to integration concerns. The isolated patch format reduces deployment friction but still requires immediate action. Procurement records show many large retailers operate multi-year Adobe contracts without mandatory rapid-patch SLAs, leaving customer data exposed during the disclosure-to-fix window.
Expect continued scanning and scripted exploitation attempts against unpatched endpoints through the next 30 days. Organizations should prioritize the isolated patch and monitor for anomalous session activity in Commerce logs.
Sansec: Exploitation attempts will surpass 500 unique source IPs within 72 hours of advisory publication.
Sources (3)
- [1]Primary Source(https://www.securityweek.com/adobe-commerce-bug-targeted-immediately-after-disclosure/)
- [2]Supporting Source(https://sansec.io/research/adobe-commerce-cve-2026-71362)
- [3]Supporting Source(https://helpx.adobe.com/security/products/commerce/apsb26-xx.html)