CISA lists Adobe Commerce and Magento account-hijack flaw as exploited, with a 27 September deadline
EditorialBy TrustList Editorial
CVE-2026-71362 lets an attacker switch a shopper into another customer's account without logging in. It is now on CISA's exploited list, and a second Commerce flaw from September also needs patching.
About CISA lists Adobe Commerce and Magento account-hijack flaw as exploited, with a 27 September deadline
CISA lists Adobe Commerce and Magento account-hijack flaw as exploited, with a 27 September deadline
24 September 2026 — The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-71362, an incorrect-authorisation flaw in Adobe Commerce and Magento Open Source, to its Known Exploited Vulnerabilities catalogue on 24 September 2026. US federal agencies must fix it by 27 September. For everyone else the catalogue is simply the most reliable public list of flaws that attackers are known to be using, and this one sits in the software that runs a large share of mid-sized online shops.
What the flaw does
Adobe rates the flaw 9.1 out of 10. An attacker who is not logged in can move a shopper's session into another customer's account, and so see that account's orders, addresses and other private details. No action by the victim is needed. Adobe fixed it in security bulletin APSB26-92, released on 11 August 2026. At the time Adobe said it knew of no attacks, but the e-commerce security firm Sansec reported blocking exploitation attempts within days, as BleepingComputer and SecurityWeek reported on 12 and 13 August.
Affected versions are Adobe Commerce, Commerce B2B and Magento Open Source up to and including the July 2026 patch levels: 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier.
Why the August patch is not enough
A second Commerce flaw, CVE-2026-75650, has been on the same exploited list since 8 September. It allows unauthenticated code execution and was fixed separately in bulletin APSB26-146, whose support page Adobe last updated on 21 September. A shop that applied the August fix and stopped there is still exposed to the September one. The two need to be checked together.
Who is affected
Any business that runs Adobe Commerce or Magento itself, or pays an agency or host to run it, is in scope. Shops on a managed Commerce service still need to know when their provider applied each fix, because the account-hijack flaw has been attacked since mid-August and customer data may already have been read.
What to do
- Confirm that both APSB26-92 (August) and APSB26-146 (September) are installed. Record the date each was applied.
- If the August fix went in late, review customer-account activity from 11 August onwards for signs of one customer's session being moved into another account.
- If an agency or host runs the store, ask it in writing for the patch level and the date of each patch, and whether it has checked for signs of exploitation.
- If customer data may have been exposed, involve whoever handles data-protection incidents: in the UK a personal data breach must be reported to the regulator within 72 hours of becoming aware of it.
Sources
- CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog — 24 September 2026
- CISA Known Exploited Vulnerabilities catalogue, JSON feed (read 25 September 2026) — 25 September 2026
- Adobe Experience League: Security update available for Adobe Commerce, APSB26-92 (updated 5 September 2026) — 5 September 2026
- Adobe Experience League: Urgent action required, APSB26-146 (updated 21 September 2026) — 21 September 2026
- BleepingComputer: Hackers exploit critical Adobe Commerce flaw to hijack customer accounts — 12 August 2026
- SecurityWeek: Adobe Commerce bug targeted immediately after disclosure — 13 August 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.