Security Affairs
Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains|50,000 Stripe Secrets Leaked in Public Code|U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog|Hackers Expose Data of 1.2 Million Heights Finance Customers|Project noRecognition: Teaching AI to Fool Surveillance Cameras|GitLab Patches Critical Unauthenticated GraphQL Vulnerability|U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog|New Mirai-Based Evooo1Bot Botnet Targets Linux Devices|SafePal Says 39,798 Customers Hit by Data Breach|LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected|Invisible AI Prompts Trigger Court Sanctions|McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen|Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains|50,000 Stripe Secrets Leaked in Public Code|U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog|Hackers Expose Data of 1.2 Million Heights Finance Customers|Project noRecognition: Teaching AI to Fool Surveillance Cameras|GitLab Patches Critical Unauthenticated GraphQL Vulnerability|U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog|New Mirai-Based Evooo1Bot Botnet Targets Linux Devices|SafePal Says 39,798 Customers Hit by Data Breach|LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected|Invisible AI Prompts Trigger Court Sanctions|McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure

Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers began targeting CVE-2026-71362 (CVSS score of 9.1), a critical Adobe Commerce flaw, shortly after its public disclosure. The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data. Cybersecurity firm […]

Adobe Commerce

Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data.

Hackers began targeting CVE-2026-71362 (CVSS score of 9.1), a critical Adobe Commerce flaw, shortly after its public disclosure. The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data.

Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory. The flaw affects Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches. Adobe released an isolated fix and urged users to patch.

“Adobe has released APSB26-92 as isolated patch files. The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9.1. Sansec Shield already blocks exploitation attempts.” reads the advisory published by Sansec. “Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data.”

Sansec pointed out that an attacker can exploit the flaw without existing account, administrator privileges, or user interaction.

Adobe fixed how Magento handles customer identity in account sessions. The remaining flaws include stored cross-site scripting and authorization issues.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Adobe)