{"id":242611,"date":"2026-08-13T01:17:24","date_gmt":"2026-08-13T06:17:24","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/08\/hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts"},"modified":"2026-08-13T01:17:24","modified_gmt":"2026-08-13T06:17:24","slug":"hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/08\/hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts","title":{"rendered":"Hackers exploit critical Adobe Commerce flaw to hijack customer accounts"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts2.jpg\"><\/a><\/p>\n<p>Attempts to exploit a critical vulnerability (CVE-2026\u201371362) in Adobe\u2019s Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.<\/p>\n<p>The flaw is described as an incorrect authorization vulnerability that could be leveraged to \u201cgain elevated access to sensitive resources\u201d without authentication and is one of the seven issues that Adobe addressed in a security update yesterday.<\/p>\n<p>Although the software vendor states in the <a href=\"http:\/\/helpx.adobe.com\/security\/products\/magento\/apsb26-92.html\" rel=\"nofollow noopener\" target=\"_blank\">advisory<\/a> that it is not aware of exploits in the wild for any of the fixed flaws, eCommerce security company Sansec says that its Shield web application firewall (WAF) is already blocking CVE-2026\u201371362 exploitation attempts.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attempts to exploit a critical vulnerability (CVE-2026\u201371362) in Adobe\u2019s Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. The flaw is described as an incorrect authorization vulnerability that could be leveraged to \u201cgain elevated access to sensitive resources\u201d without authentication and is one of the seven issues that Adobe [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1492],"tags":[],"class_list":["post-242611","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242611","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=242611"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242611\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=242611"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=242611"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=242611"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}