Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The AI-Generated Pattern Hides You From Surveillance Cameras—Including Flock

    August 12, 2026

    NASA Data Helps Commercial Space Plan Living Off Our Moon 

    August 12, 2026

    Nickel expansion puts Indonesia’s biodiversity goals under pressure, study finds

    August 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The AI-Generated Pattern Hides You From Surveillance Cameras—Including Flock
    • NASA Data Helps Commercial Space Plan Living Off Our Moon 
    • Nickel expansion puts Indonesia’s biodiversity goals under pressure, study finds
    • What Does the Mecca Pact Deliver Pakistan? – Foreign Policy
    • Is this image of Trump hiding in plane catering cart authentic? Don’t believe your eyes
    • Trump administration plans to give ICE officers electric-shock gloves | Donald Trump News
    • South Carolina Senate Runoff Kicks Off With Chick-fil-A and Trump Calls
    • Karoline Leavitt, Trump’s White House Press Secretary, Is Leaving the Role
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 12, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe’s Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.

    The flaw is described as an incorrect authorization vulnerability that could be leveraged to “gain elevated access to sensitive resources” without authentication and is one of the seven issues that Adobe addressed in a security update yesterday.

    Although the software vendor states in the advisory that it is not aware of exploits in the wild for any of the fixed flaws, eCommerce security company Sansec says that its Shield web application firewall (WAF) is already blocking CVE-2026-71362 exploitation attempts.

    image

    According to Sansec, exploiting the vulnerability requires “no existing account, administrator privileges or user interaction.”

    After analyzing Adobe’s patch, the researchers pinned the problem to Magento improperly handling customer identity in an account session.

    “Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data,” the security company explains.

    Four of the other flaws Adobe fixed with yesterday’s updates received a high-severity score, and the other two are medium and low severity:

    • CVE-2026-48414 (7.7, high severity): Stored cross-site scripting vulnerability that could result in arbitrary code execution. Exploitation requires authentication and administrator privileges.
    • CVE-2026-48413 (8.7, high severity): Stored cross-site scripting vulnerability that could result in arbitrary code execution. It requires authentication but not administrator privileges.
    • CVE-2026-48415 (7.6, high severity): Incorrect-authorization vulnerability affecting Adobe Commerce B2B that could enable a security-feature bypass. It requires authentication but not administrator privileges.
    • CVE-2026-48416 (7.5, high severity): Incorrect-authorization vulnerability that could enable a security-feature bypass. It requires neither authentication nor administrator privileges.
    • CVE-2026-48411 (6.5, medium severity): Incorrect-authorization vulnerability that could enable a security-feature bypass. Exploitation requires authentication and administrator privileges.
    • CVE-2026-48412 (2.7, low severity): Incorrect-authorization vulnerability that could result in privilege escalation. Exploitation requires authentication and administrator privileges.

    Website administrators are advised to apply the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible.

    According to Sansec, these monthly fixes are distributed as isolated patch files rather than a new security release or updated Composer packages.

    Website admins must first ensure they’re running the latest -p release available for their supported release branch before applying the corresponding isolated patch.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Accounts Adobe commerce critical customer exploit Flaw hackers hijack
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Enterprise Defenses Recovered at the Edge and Collapsed Inside

    OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning

    Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

    Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Hackers are hunting for your private photos, FBI warns: 6 ways to avoid a sextortion nightmare

    737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The AI-Generated Pattern Hides You From Surveillance Cameras—Including Flock

    August 12, 2026

    NASA Data Helps Commercial Space Plan Living Off Our Moon 

    August 12, 2026

    Nickel expansion puts Indonesia’s biodiversity goals under pressure, study finds

    August 12, 2026

    What Does the Mecca Pact Deliver Pakistan? – Foreign Policy

    August 12, 2026
    Latest Posts

    Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO

    July 25, 2026

    Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration

    July 25, 2026

    Did Trump collapse while trying to get into vehicle?

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The AI-Generated Pattern Hides You From Surveillance Cameras—Including Flock

    August 12, 2026

    NASA Data Helps Commercial Space Plan Living Off Our Moon 

    August 12, 2026

    Nickel expansion puts Indonesia’s biodiversity goals under pressure, study finds

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.