Breaking NewsUpdated as information becomes available
Breach Analysis·14 August 2026·Breaking

Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
Graphic illustration representing e-commerce session security and software patch management
Breach Analysis

Article record

Breach AnalysisCategory
14 August 2026Published
4 min readReading time
Mark FermorWritten by
Graphic illustration representing e-commerce session security and software patch management

Why it matters

What this means for organisations holding critical data

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

SecurityWeek has reported that malicious actors began targeting a fresh, critical severity vulnerability in Adobe Commerce immediately after its public disclosure. Security firm Sansec detected and blocked the initial exploitation attempts shortly after Adobe published its advisory for the flaw, which is tracked as CVE-2026-71362. The security defect carries a Common Vulnerability Scoring System score of 9.1 and affects Adobe Commerce, Adobe Commerce B2B, and Magento Open Source versions up to and including those running the July 2026 patches.

What happened

According to findings published by webstore security firm Sansec and reported by SecurityWeek, the vulnerability stems from an incorrect authorisation issue within the application. This weakness allows remote, unauthenticated attackers to elevate their privileges without valid credentials.

Sansec reviewed the software fix and confirmed that the flaw allows attackers to switch an active customer session to that of another customer account. By manipulating account sessions, an attacker gains unauthorised access to the target account and all associated private customer data.

Adobe addressed the issue on its August 2026 Patch Tuesday, releasing an isolated security patch alongside fixes for six other security defects in the affected products. In its official documentation, Adobe noted that it had no prior evidence of exploitation before release, but warned that threat actors have historically targeted Commerce software. The software vendor urged merchants to apply the isolated patch as quickly as possible to prevent potential arbitrary code execution, security feature bypass, and privilege escalation. Adobe stated that providing an isolated patch allows merchants to apply the fix without unnecessary delay from integration issues.

What the data means for the sector

The rapid onset of automated exploitation following security advisories highlights the shrinking window of protection for e-commerce operators. When software vendors publish security advisories and code patches, threat actors immediately reverse engineer the fixes to build working exploits. In this instance, Sansec observed active attack attempts targeting the flaw almost instantly after public details were made available.

For retail and e-commerce organisations, webstore platforms hold highly sensitive consumer records, transactional data, and operational credentials. When session management mechanisms fail, live web application environments expose customer databases directly to the public internet. This environment forces security teams into a reactive posture where live systems remain exposed until patches are fully deployed and verified.

While rapid patch management for internet facing storefronts is essential, relying solely on live infrastructure creates operational exposure. Online databases and live administration panels remain vulnerable to zero day defects and immediate post disclosure attacks. If an attacker gains elevated access through a session management flaw, connected cloud backups and network attached storage endpoints can be enumerated and compromised from within the administrative perimeter.

The Firevault view

"When an authentication flaw opens live customer sessions to external manipulation, online systems are inherently vulnerable during the interval between disclosure and patching," states Mark Fermor at Firevault. "Immediate post disclosure exploitation demonstrates that perimeter defences and rapid patching alone cannot guarantee the integrity of critical data archives."

At Firevault, we advocate for the implementation of Offline Secure Storage® (#OSS) to protect core business records, database backups, and customer registers from network based threats. A physically disconnected copy changes the recovery balance entirely during an application breach.

When critical database backups and transaction records are stored via #OSS, they reside on physically isolated media that cannot be accessed, altered, or wiped over a network connection, regardless of privilege escalation on the web server. Even if an unauthenticated attacker successfully takes over administrative sessions on an Adobe Commerce deployment, they cannot reach, modify, or corrupt air gapped archives. This physical barrier ensures that an organisation retains clean, authoritative copies of its critical data assets to support incident response and rapid business restoration.

What to do next

  • Apply the isolated Adobe security patch for CVE-2026-71362 immediately across all impacted Commerce and Magento installations.
  • Audit active customer sessions and administrative logs for any indicators of session switching or unauthorised access following disclosure.
  • Review network architecture to ensure critical customer database backups are isolated from live web application environments.
  • Establish an air gapped backup routine using #OSS to protect core transaction logs and customer records from network based manipulation.
  • Verify that automated security monitoring is configured to detect unusual session modifications or privilege escalation attempts.

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Breaking News
Breach Analysis14 August 20264 min read

Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

Adobe Commerce attacked immediately after session breach vulnerability
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy