CuraSec

Act active

Active Exploitation of Critical Adobe Commerce Account-Hijack Flaw

2026-08-13 11:57 UTC · BleepingComputer · read the source ↗ #adobe-commerce#cve#active-exploitation
  • Engineer — Act: Active exploitation attempts against CVE-2026-71362 in Adobe Commerce and Magento have been observed despite low EPSS — if you run either platform, patch immediately and audit recent customer authentication logs for signs of account takeover.
  • SOC/IR — Plan: No IOCs or ATT&CK-mapped TTPs are available yet, but active exploitation is reported; build or tune detections for anomalous authentication patterns and privilege changes on Commerce/Magento instances in your estate.
  • Leader — Plan: If your organization or a key e-commerce vendor runs Adobe Commerce or Magento, confirm patching status this week and assess whether customer account data may have been exposed, given the reported exploitation activity.
  • Signals: CVE-2026-71362 — CISA KEV: not listed, EPSS 0.00, no public PoC found
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.