logo

Warning: Actively Exploited Critical Vulnerability in Adobe Commerce, Patch Immediately!

ID: 559452df-9bff-5851-81a5-678158a730b4

STIX ID: report--559452df-9bff-5851-81a5-678158a730b4

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
90/100

Date Published: 2026-08-17

Date Updated: 2026-08-17

...
...

Adobe published a security bulletin on 11 August 2026 reporting seven network-exploitable vulnerabilities in Adobe Commerce, Adobe Commerce B2B and Magento Open Source (five rated critical). The most severe, CVE-2026-71362 (CVSS 9.1), is an unauthenticated incorrect authorization flaw enabling privilege escalation and session swapping to expose customer data; active exploitation has been reported. The Centre for Cybersecurity Belgium and Adobe recommend immediate patching and increased monitoring, and note that patching does not remediate prior compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.