A critical security flaw in Adobe Commerce and Magento, the platforms behind many online shops, is being actively exploited. The US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities list on 24 September 2026.
- What it is: A flaw (CVE-2026-71362, rated 9.1 out of 10) that lets an attacker switch into another customer's account on your store without needing a password or login.
- Who is affected: Any business running Adobe Commerce, Adobe Commerce B2B or Magento Open Source on versions up to and including the July 2026 patches.
- The risk: Attackers can view private customer details such as names, addresses and order history. For Australian businesses this may trigger obligations under the Notifiable Data Breaches scheme.
- Status: Adobe released a fix in August 2026 (security bulletin APSB26-92), including an isolated patch that can be applied on its own. Security researchers saw attack attempts almost immediately after the fix was published.
- What to do: Ask your web developer or hosting provider to confirm the August 2026 update or isolated patch has been applied, and to review logs for unusual customer account activity since mid-August.
If your online store runs on Magento or Adobe Commerce and you are not sure it has been patched, we recommend checking with your developer today.
Sources: CISA, Adobe Security Bulletin APSB26-92, SecurityWeek