---
title: "Adobe Commerce attacked immediately after sessi… | Firevault"
description: "Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/adobe-commerce-session-vulnerability-exploited-after-disclosure#webpage",
      "url": "https://fire-vault.com/news/adobe-commerce-session-vulnerability-exploited-after-disclosure",
      "name": "Adobe Commerce attacked immediately after sessi…",
      "description": "Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/adobe-commerce-session-vulnerability-exploited-after-disclosure#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/adobe-commerce-session-vulnerability-exploited-after-disclosure#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Adobe Commerce attacked immediately after session breach vulnerability",
          "item": "https://fire-vault.com/news/adobe-commerce-session-vulnerability-exploited-after-disclosure"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Adobe Commerce attacked immediately after session breach vulnerability",
      "description": "Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.",
      "url": "https://fire-vault.com/news/adobe-commerce-session-vulnerability-exploited-after-disclosure",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-08-14T05:17:44.05+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/adobe-commerce-session-vulnerability-exploited-after-disclosure"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 687,
      "keywords": "Adobe, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "SecurityWeek has reported that malicious actors began targeting a fresh, critical severity vulnerability in Adobe Commerce immediately after its public disclosure. Security firm Sansec detected and blocked the initial exploitation attempts shortly after Adobe published its advisory for the flaw, which is tracked as CVE-2026-71362. The security defect carries a Common Vulnerability Scoring System s",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Overview

What happenedWhat the data means for the sectorThe Firevault viewWhat to do nextMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 14 August 2026 

# Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fadobe-commerce-session-vulnerability-exploited-after-disclosure)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fadobe-commerce-session-vulnerability-exploited-after-disclosure&text=Adobe%20Commerce%20attacked%20immediately%20after%20session%20breach%20vulnerability%0A%0ASecurity%20firm%20Sansec%20blocked%20attacks%20targeting%20Adobe%20Commerce%20immediately%20after%20disclosure.%20The%20flaw%20allows%20unauthenticated%20attackers%20to%20hijack%20sessions%20and%20customer%20data.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fadobe-commerce-session-vulnerability-exploited-after-disclosure)[](mailto:?subject=Adobe%20Commerce%20attacked%20immediately%20after%20session%20breach%20vulnerability&body=Security%20firm%20Sansec%20blocked%20attacks%20targeting%20Adobe%20Commerce%20immediately%20after%20disclosure.%20The%20flaw%20allows%20unauthenticated%20attackers%20to%20hijack%20sessions%20and%20customer%20data.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fadobe-commerce-session-vulnerability-exploited-after-disclosure)

![Graphic illustration representing e-commerce session security and software patch management](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Graphic illustration representing e-commerce session security and software patch management

Why it matters

## What this means for organisations holding critical data

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [What the data means for the sector](#section-1)
3.  03 [The Firevault view](#section-2)

**On this page**[What happened](#section-0)[What the data means for the sector](#section-1)[The Firevault view](#section-2)

SecurityWeek has reported that malicious actors began targeting a fresh, critical severity vulnerability in Adobe Commerce immediately after its public disclosure. Security firm Sansec detected and blocked the initial exploitation attempts shortly after Adobe published its advisory for the flaw, which is tracked as CVE-2026-71362. The security defect carries a Common Vulnerability Scoring System score of 9.1 and affects Adobe Commerce, Adobe Commerce B2B, and Magento Open Source versions up to and including those running the July 2026 patches.

## What happened

According to findings published by webstore security firm Sansec and reported by SecurityWeek, the vulnerability stems from an incorrect authorisation issue within the application. This weakness allows remote, unauthenticated attackers to elevate their privileges without valid credentials.

Sansec reviewed the software fix and confirmed that the flaw allows attackers to switch an active customer session to that of another customer account. By manipulating account sessions, an attacker gains unauthorised access to the target account and all associated private customer data.

Adobe addressed the issue on its August 2026 Patch Tuesday, releasing an isolated security patch alongside fixes for six other security defects in the affected products. In its official documentation, Adobe noted that it had no prior evidence of exploitation before release, but warned that threat actors have historically targeted Commerce software. The software vendor urged merchants to apply the isolated patch as quickly as possible to prevent potential arbitrary code execution, security feature bypass, and privilege escalation. Adobe stated that providing an isolated patch allows merchants to apply the fix without unnecessary delay from integration issues.

## What the data means for the sector

The rapid onset of automated exploitation following security advisories highlights the shrinking window of protection for e-commerce operators. When software vendors publish security advisories and code patches, threat actors immediately reverse engineer the fixes to build working exploits. In this instance, Sansec observed active attack attempts targeting the flaw almost instantly after public details were made available.

For retail and e-commerce organisations, webstore platforms hold highly sensitive consumer records, transactional data, and operational credentials. When session management mechanisms fail, live web application environments expose customer databases directly to the public internet. This environment forces security teams into a reactive posture where live systems remain exposed until patches are fully deployed and verified.

While rapid patch management for internet facing storefronts is essential, relying solely on live infrastructure creates operational exposure. Online databases and live administration panels remain vulnerable to zero day defects and immediate post disclosure attacks. If an attacker gains elevated access through a session management flaw, connected cloud backups and network attached storage endpoints can be enumerated and compromised from within the administrative perimeter.

## The Firevault view

_"When an authentication flaw opens live customer sessions to external manipulation, online systems are inherently vulnerable during the interval between disclosure and patching,"_ states Mark Fermor at Firevault. _"Immediate post disclosure exploitation demonstrates that perimeter defences and rapid patching alone cannot guarantee the integrity of critical data archives."_

At Firevault, we advocate for the implementation of [Offline Secure Storage](/offline-secure-storage)® (#OSS) to protect core business records, database backups, and customer registers from network based threats. A physically disconnected copy changes the recovery balance entirely during an application breach.

When critical database backups and transaction records are stored via #OSS, they reside on physically isolated media that cannot be accessed, altered, or wiped over a network connection, regardless of privilege escalation on the web server. Even if an unauthenticated attacker successfully takes over administrative sessions on an Adobe Commerce deployment, they cannot reach, modify, or corrupt air gapped archives. This physical barrier ensures that an organisation retains clean, authoritative copies of its critical data assets to support incident response and rapid business restoration.

## What to do next

-   Apply the isolated Adobe security patch for CVE-2026-71362 immediately across all impacted Commerce and Magento installations.
-   Audit active customer sessions and administrative logs for any indicators of session switching or unauthorised access following disclosure.
-   Review network architecture to ensure critical [customer database](/oss-for-customer-databases) backups are isolated from live web application environments.
-   Establish an air gapped backup routine using #OSS to protect core transaction logs and customer records from network based manipulation.
-   Verify that automated security monitoring is configured to detect unusual session modifications or privilege escalation attempts.

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.securityweek.com/adobe-commerce-bug-targeted-immediately-after-disclosure/)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later](/news/hcrg-care-group-children-records-cyber-attack-2026.jpg)

Breach Analysis 

### Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later

Families of vulnerable children in Wiltshire, Bath and North East Somerset have been told their personal health information may have been accessed in a cyber attack on HCRG Care Group in February 2025, more than 18 months after the incident.

20 Sept 2026 4 min 







](/news/hcrg-care-group-children-records-cyber-attack-2026)[

![FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters](/news/us-coast-guard-tanker-cyberattacks-2026.jpg)

Breach Analysis 

### FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

17 Sept 2026 4 min 







](/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026)[

![FBI investigates 153 million drivers licenses put up for sale on a criminal forum](/news/fbi-drivers-licenses-dark-web-2026.jpg)

Breach Analysis 

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min 







](/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026)[

![CenterPoint Energy confirms hackers stole customer data through an exposed API](/news/centerpoint-energy-cyberattack-2026.jpg)

Breach Analysis 

### CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

16 Sept 2026 4 min 







](/news/centerpoint-energy-confirms-cyberattack-data-theft-2026)[

![Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details](/news/southampton-council-data-breaches-2026.jpg)

Breach Analysis 

### Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details

Southampton City Council referred seven incidents to the Information Commissioner's Office in 2025/26, including a social worker's lost notebook containing the names, addresses and key safe numbers of 224 people. Mark Fermor on what a notebook, a miscatalogued archive and a curious officer tell us about the data organisations still cannot control.

16 Sept 2026 5 min 







](/news/southampton-council-seven-serious-data-breaches-2026)[

![Southport court files breach: the access was authorised, the purpose was not](/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg)

Breach Analysis 

### Southport court files breach: the access was authorised, the purpose was not

The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without authorisation. It is the third insider access case connected to the attack, and it shows why perimeter security alone cannot protect the most sensitive records.

16 Sept 2026 5 min 







](/news/southport-court-files-insider-access-breach-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)