Home/Blog/Magento 2
Magento 2·6 min read

By Yash Patel, Founder, Kevion Technologies

Critical Adobe Commerce Flaw (CVE-2026-71362): Patch Now, Even If You're Fully Supported

Adobe's August 2026 bulletin patches a CVSS 9.1 account-takeover flaw in Adobe Commerce and Magento Open Source. It needs no login or admin access, and attackers are already probing for it.

On August 11, 2026, Adobe published security bulletin APSB26-92 for Adobe Commerce and Magento Open Source, fixing seven vulnerabilities, five of them rated Critical. The one that matters most for every store running on the platform is CVE-2026-71362: a CVSS 9.1 account-takeover flaw that requires no authentication, no admin access, and no action from the victim. If you run Adobe Commerce or Magento and haven't applied this isolated patch yet, this is the post to stop and act on.

What's actually broken

CVE-2026-71362 is an incorrect authorization vulnerability (CWE-863): the platform fails to correctly bind a customer's identity to their account session. In practice, that means an attacker can hijack an active session and move it to a different customer's account, reaching that person's saved addresses, order history, and stored payment methods. No credentials are needed, no admin privileges are needed, and the victim doesn't have to click, open, or approve anything. It's the kind of flaw that turns a single unpatched storefront into a mass data-exposure incident rather than an isolated one.

Why "we're on a supported version" doesn't cover you here

This is a different story from Magento 2.4.5/2.4.6 losing regular security support, which we covered when it happened. That story was about being on an old, unsupported line. This one hits current, fully supported releases too: Adobe Commerce 2.4.4 through 2.4.9 and Magento Open Source 2.4.6 through 2.4.9, specifically builds at the -2026-jul patch level or earlier. Being current on your release doesn't protect you against this vulnerability; only applying the isolated August patch does.

  • Adobe Commerce: patched builds are 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, and 2.4.4-2026-aug, plus the corresponding B2B editions.
  • Magento Open Source: equivalent -2026-aug builds across the 2.4.6–2.4.9 lines.
  • If your store is on a line older than 2.4.4 for Commerce or 2.4.6 for Open Source, this bulletin doesn't have a build for you. That means the platform is old enough that an upgrade plan is overdue, not just a patch.

The exploitation timeline is the part that should push this up your queue

Adobe had no evidence of active exploitation when the bulletin went out on August 11. Sansec, which monitors Magento/Adobe Commerce stores for compromise, began detecting and blocking exploitation attempts within roughly a day of disclosure. That gap, public patch to attacks within 24 hours, is now the normal timeline for critical, unauthenticated Magento vulnerabilities, not an exception. Store owners who treat a security bulletin as "something to schedule for next sprint" are routinely losing that race.

No successful, publicly confirmed compromises via this CVE have been disclosed as of this writing. That is not the same as "safe to wait". It's a CVSS 9.1 flaw that needs no login and no action from the victim, and it's already being probed. Treat it as urgent regardless of confirmed breach counts.

What to do this week

  1. Confirm your exact Adobe Commerce or Magento Open Source build, including the patch level, not only the major version.
  2. Apply the -2026-aug isolated patch (or the composer-based equivalent) for your specific release line as soon as a maintenance window allows.
  3. If you're on a version predating this bulletin's coverage, treat the platform upgrade itself as the priority, since it's no longer receiving isolated security patches at all.
  4. After patching, check for signs of earlier compromise, such as unexpected admin users, unfamiliar customer session activity or unrecognised changes to stored payment methods. The flaw existed before it was disclosed.
  5. If you manage multiple Magento/Adobe Commerce stores across an agency or in-house team, patch by risk: highest-traffic and highest-order-value stores first.

If you're not confident about your current patch level, or you're maintaining a Magento/Adobe Commerce store without a dedicated development team watching security bulletins as they land, that's the gap our Magento 2 team fills for clients through maintenance and support. Tell us about your store if you need this patch applied or your build audited before it becomes an incident.

Frequently Asked Questions

What does CVE-2026-71362 actually let an attacker do?

It's an incorrect authorization flaw (CWE-863) that fails to properly bind a customer identity to an account session. An attacker can switch an active session to a different customer's account and reach that victim's saved addresses, order history, and stored payment methods, with no account of their own, no admin privileges, and no user interaction required from the victim.

Which Adobe Commerce and Magento versions are affected?

Adobe Commerce release lines 2.4.4 through 2.4.9, and Magento Open Source release lines 2.4.6 through 2.4.9, at the -2026-jul build and earlier. This includes fully supported, up-to-date versions, not only the 2.4.5/2.4.6 lines that recently lost regular security support. Being current on releases doesn't protect you here; only the isolated patch does.

Is this actively being exploited?

Adobe had no evidence of in-the-wild exploitation when it published the bulletin on August 11, 2026, but Sansec detected and began blocking exploitation attempts within about a day. No successful, publicly confirmed compromises have been disclosed yet, but a CVSS 9.1, unauthenticated, no-interaction flaw being actively probed this soon after disclosure is exactly the profile that turns into mass exploitation if stores don't patch.

Magento 2Adobe CommerceSecurityE-commerce

Planning a Magento migration or build?

We offer a free 30-minute audit: extension review, a timeline estimate and an honest view of the scope.

Book a Migration Audit
Related service

Magento 2 Development

Custom Magento 2 modules, B2B pricing and quote workflows, ERP integrations, Magento 1 to 2 migrations and performance fixes. We also build Shopify apps for teams that run both platforms.

How we can help →
Magento· Healthcare & WellnessUnder NDA

Magento 2 Migration and Performance: Online Healthcare Store

Problem
Magento 1 had reached end-of-life, and pages and checkout slowed or failed whenever traffic peaked.
What we did
Two engagements for one online healthcare store: a Magento 1 to Magento 2 migration, then a performance and AWS infrastructure overhaul as traffic grew.
Magento 2MigrationPerformanceAWS

Get new articles by email

Practical Magento, Shopify, Laravel & AI guides, about once a month. Unsubscribe anytime.

Stay Updated

Occasional articles on web development, e-commerce and AI. No spam.

Adobe Commerce CVE-2026-71362 Patch Guide | Kevion