"Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim's account and private customer data," the security company explains.
CVE-2026-71362: session switching that needs no account
Adobe's Commerce and Magento platforms contain a critical vulnerability tracked as CVE-2026-71362 that researchers describe as an incorrect-authorization bug. According to the vendor's advisory, the flaw could be leveraged to "gain elevated access to sensitive resources" without authentication. Sansec's analysis of Adobe's patch traces the root cause to Magento improperly handling customer identity in an account session, allowing an attacker to switch a customer session to another customer's account.
Sansec says exploitation attempts are being blocked
Adobe's official advisory states it is not aware of exploits in the wild for any of the fixed flaws. Sansec, an eCommerce security firm, reports a different immediate reality: its Shield web application firewall (WAF) is already blocking attempts to exploit CVE-2026-71362. Sansec also notes that exploiting the vulnerability requires "no existing account, administrator privileges or user interaction," a combination which raises the risk profile for large installations with many active customer sessions.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleOther vulnerabilities fixed in Adobe's August 2026 update
Adobe closed seven issues in the update released yesterday. Four of those received high-severity scores, and the rest were medium or low. The security advisory lists them with their CVE identifiers, severity scores, and the conditions required for exploitation:
- CVE-2026-48414 (7.7, high severity): Stored cross-site scripting vulnerability that could result in arbitrary code execution. Exploitation requires authentication and administrator privileges.
- CVE-2026-48413 (8.7, high severity): Stored cross-site scripting vulnerability that could result in arbitrary code execution. It requires authentication but not administrator privileges.
- CVE-2026-48415 (7.6, high severity): Incorrect-authorization vulnerability affecting Adobe Commerce B2B that could enable a security-feature bypass. It requires authentication but not administrator privileges.
- CVE-2026-48416 (7.5, high severity): Incorrect-authorization vulnerability that could enable a security-feature bypass. It requires neither authentication nor administrator privileges.
- CVE-2026-48411 (6.5, medium severity): Incorrect-authorization vulnerability that could enable a security-feature bypass. Exploitation requires authentication and administrator privileges.
- CVE-2026-48412 (2.7, low severity): Incorrect-authorization vulnerability that could result in privilege escalation. Exploitation requires authentication and administrator privileges.
Patch distribution and the deployment constraint administrators must note
Sansec warns that Adobe's monthly fixes are issued as isolated patch files rather than as a new consolidated security release or updated Composer packages. Website administrators must first ensure they are running the latest -p release available for their supported release branch before applying the corresponding isolated patch. Adobe specifically advises administrators to apply the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible.
What this means for website administrators, security teams, and end users
- Website administrators: The immediate task is operational — confirm the current -p release for your branch, obtain the isolated patch files, and apply the August 2026 update for Commerce, Commerce B2B, or Magento without delay. Administrators should also review WAF logs and any Shield WAF alerts if they use Sansec's tooling.
- Security teams and technologists: Sansec's finding that exploitation requires no account or interaction and that its WAF is blocking attempts indicates active probing or exploitation attempts despite Adobe's statement of no known in-the-wild exploits. Teams should prioritize session-management auditing and monitor for anomalous session-switch events. The Blue Report 2026 note in the advisory material also highlights that "overall prevention scores can hide what happens after initial access," underscoring that controls can weaken once valid credentials or sessions are leveraged.
- End users (customers of affected sites): Because the vulnerability can give attackers access to a victim's account and private customer data, users should monitor account activity and contact merchants if they see unexpected orders, address changes, or messages that indicate account takeover.
Adobe and Sansec present two linked facts: the vendor patched seven vulnerabilities in yesterday's update and states it is not aware of in-the-wild exploitation, while Sansec reports active blocking of exploitation attempts against CVE-2026-71362. For operators of Commerce and Magento stores that still run supported release branches, the practical response is concrete and immediate — verify your -p release, apply the isolated patch files for the August 2026 update, and review session-handling logs and WAF telemetry to detect any evidence of the session-switching technique Sansec describes.




