Adobe Commerce attacked immediately after session breach vulnerability
Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.
Article record
Why it matters
What this means for organisations holding critical data
Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.
SecurityWeek has reported that malicious actors began targeting a fresh, critical severity vulnerability in Adobe Commerce immediately after its public disclosure. Security firm Sansec detected and blocked the initial exploitation attempts shortly after Adobe published its advisory for the flaw, which is tracked as CVE-2026-71362. The security defect carries a Common Vulnerability Scoring System score of 9.1 and affects Adobe Commerce, Adobe Commerce B2B, and Magento Open Source versions up to and including those running the July 2026 patches.
What happened
According to findings published by webstore security firm Sansec and reported by SecurityWeek, the vulnerability stems from an incorrect authorisation issue within the application. This weakness allows remote, unauthenticated attackers to elevate their privileges without valid credentials.
Sansec reviewed the software fix and confirmed that the flaw allows attackers to switch an active customer session to that of another customer account. By manipulating account sessions, an attacker gains unauthorised access to the target account and all associated private customer data.
Adobe addressed the issue on its August 2026 Patch Tuesday, releasing an isolated security patch alongside fixes for six other security defects in the affected products. In its official documentation, Adobe noted that it had no prior evidence of exploitation before release, but warned that threat actors have historically targeted Commerce software. The software vendor urged merchants to apply the isolated patch as quickly as possible to prevent potential arbitrary code execution, security feature bypass, and privilege escalation. Adobe stated that providing an isolated patch allows merchants to apply the fix without unnecessary delay from integration issues.
What the data means for the sector
The rapid onset of automated exploitation following security advisories highlights the shrinking window of protection for e-commerce operators. When software vendors publish security advisories and code patches, threat actors immediately reverse engineer the fixes to build working exploits. In this instance, Sansec observed active attack attempts targeting the flaw almost instantly after public details were made available.
For retail and e-commerce organisations, webstore platforms hold highly sensitive consumer records, transactional data, and operational credentials. When session management mechanisms fail, live web application environments expose customer databases directly to the public internet. This environment forces security teams into a reactive posture where live systems remain exposed until patches are fully deployed and verified.
While rapid patch management for internet facing storefronts is essential, relying solely on live infrastructure creates operational exposure. Online databases and live administration panels remain vulnerable to zero day defects and immediate post disclosure attacks. If an attacker gains elevated access through a session management flaw, connected cloud backups and network attached storage endpoints can be enumerated and compromised from within the administrative perimeter.
The Firevault view
"When an authentication flaw opens live customer sessions to external manipulation, online systems are inherently vulnerable during the interval between disclosure and patching," states Mark Fermor at Firevault. "Immediate post disclosure exploitation demonstrates that perimeter defences and rapid patching alone cannot guarantee the integrity of critical data archives."
At Firevault, we advocate for the implementation of Offline Secure Storage® (#OSS) to protect core business records, database backups, and customer registers from network based threats. A physically disconnected copy changes the recovery balance entirely during an application breach.
When critical database backups and transaction records are stored via #OSS, they reside on physically isolated media that cannot be accessed, altered, or wiped over a network connection, regardless of privilege escalation on the web server. Even if an unauthenticated attacker successfully takes over administrative sessions on an Adobe Commerce deployment, they cannot reach, modify, or corrupt air gapped archives. This physical barrier ensures that an organisation retains clean, authoritative copies of its critical data assets to support incident response and rapid business restoration.
What to do next
- Apply the isolated Adobe security patch for CVE-2026-71362 immediately across all impacted Commerce and Magento installations.
- Audit active customer sessions and administrative logs for any indicators of session switching or unauthorised access following disclosure.
- Review network architecture to ensure critical customer database backups are isolated from live web application environments.
- Establish an air gapped backup routine using #OSS to protect core transaction logs and customer records from network based manipulation.
- Verify that automated security monitoring is configured to detect unusual session modifications or privilege escalation attempts.
Sources
Where this reporting comes from
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






