Skip to content
TrustList
News

CISA lists Adobe Commerce and Magento account-hijack flaw as exploited, with a 27 September deadline

Editorial

By TrustList Editorial

CVE-2026-71362 lets an attacker switch a shopper into another customer's account without logging in. It is now on CISA's exploited list, and a second Commerce flaw from September also needs patching.

About CISA lists Adobe Commerce and Magento account-hijack flaw as exploited, with a 27 September deadline

CISA lists Adobe Commerce and Magento account-hijack flaw as exploited, with a 27 September deadline

24 September 2026 — The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-71362, an incorrect-authorisation flaw in Adobe Commerce and Magento Open Source, to its Known Exploited Vulnerabilities catalogue on 24 September 2026. US federal agencies must fix it by 27 September. For everyone else the catalogue is simply the most reliable public list of flaws that attackers are known to be using, and this one sits in the software that runs a large share of mid-sized online shops.

What the flaw does

Adobe rates the flaw 9.1 out of 10. An attacker who is not logged in can move a shopper's session into another customer's account, and so see that account's orders, addresses and other private details. No action by the victim is needed. Adobe fixed it in security bulletin APSB26-92, released on 11 August 2026. At the time Adobe said it knew of no attacks, but the e-commerce security firm Sansec reported blocking exploitation attempts within days, as BleepingComputer and SecurityWeek reported on 12 and 13 August.

Affected versions are Adobe Commerce, Commerce B2B and Magento Open Source up to and including the July 2026 patch levels: 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier.

Why the August patch is not enough

A second Commerce flaw, CVE-2026-75650, has been on the same exploited list since 8 September. It allows unauthenticated code execution and was fixed separately in bulletin APSB26-146, whose support page Adobe last updated on 21 September. A shop that applied the August fix and stopped there is still exposed to the September one. The two need to be checked together.

Who is affected

Any business that runs Adobe Commerce or Magento itself, or pays an agency or host to run it, is in scope. Shops on a managed Commerce service still need to know when their provider applied each fix, because the account-hijack flaw has been attacked since mid-August and customer data may already have been read.

What to do

  • Confirm that both APSB26-92 (August) and APSB26-146 (September) are installed. Record the date each was applied.
  • If the August fix went in late, review customer-account activity from 11 August onwards for signs of one customer's session being moved into another account.
  • If an agency or host runs the store, ask it in writing for the patch level and the date of each patch, and whether it has checked for signs of exploitation.
  • If customer data may have been exposed, involve whoever handles data-protection incidents: in the UK a personal data breach must be reported to the regulator within 72 hours of becoming aware of it.

Sources