CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4309

As cited

Copy frozen at (site build).

vulnerabilities

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento has been detected under active exploitation. Attackers can use the flaw to hijack customer accounts on affected e-commerce platforms.

Why it matters: E-commerce operators running Adobe Commerce or Magento need to patch immediately to prevent account takeover and customer credential theft.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento e-commerce platforms has been targeted by attackers, with potential for account hijacking. The flaw carries a CVSS score of 9.1. Exploitation attempts have been observed in the wild.

Why it matters: Merchants running Adobe Commerce or Magento must apply patches immediately, as customer account compromise exposes payment data and personal information.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attackers have begun exploiting CVE-2026-71362, a critical vulnerability in Adobe Commerce and Magento platforms, to hijack customer accounts. The flaw carries a CVSS score of 9.1 and is tracked on security vendor vulnerability databases.

Why it matters: E-commerce operators running Adobe Commerce or Magento need to prioritize patching this critical flaw immediately, as active exploitation threatens customer account takeover and associated data exposure or fraud.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attackers are exploiting a critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento platforms to compromise customer accounts. The flaw carries a CVSS score of 9.1 and has been added to the Known Exploited Vulnerabilities catalog.

Why it matters: E-commerce merchants running Adobe Commerce or Magento must patch immediately to prevent account takeovers and customer data theft.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attackers are exploiting a critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento platforms to compromise customer accounts. The flaw carries a CVSS score of 9.1 and has been added to the Known Exploited Vulnerabilities catalog.

Why it matters: E-commerce merchants running Adobe Commerce or Magento must patch immediately to prevent account takeovers and customer data theft.

VendorsAdobe
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

A critical vulnerability in Adobe Commerce and Magento platforms is being exploited in active attacks. The flaw, rated 9.1 CVSS, enables attackers to hijack customer accounts on affected e-commerce sites.

Why it matters: Organizations running Adobe Commerce or Magento must patch immediately to prevent account takeovers and customer data compromise; the vulnerability is actively exploited and listed on the Known Exploited Vulnerabilities (KEV) catalog.

VendorsAdobe
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary