Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Adobe Commerce Flaw Could Let Hackers Take Over Customer Accounts

A serious security flaw has been found in Adobe Commerce that could allow attackers to gain higher access rights without needing anyone to click a link or open a file. This means hackers could potentially take over customer accounts and access sensitive information, posing a big risk to businesses using this platform.

14 August 2026

Reference: CVE-2026-71362

1. What is being reported?

Researchers have discovered a critical vulnerability in Adobe Commerce where attackers can bypass normal access controls and escalate their privileges. This means they can gain more control than they should, potentially accessing sensitive data or managing accounts without permission. The flaw can be exploited remotely and does not require any action from users.

2. What this means in plain English

If your organisation uses Adobe Commerce for online sales or customer management, this vulnerability could let hackers take control of customer accounts or sensitive business information. This could lead to data breaches, loss of customer trust, and financial damage. Because no user interaction is needed, the risk is higher as attacks can happen silently.

3. Could this affect a small business?

Small businesses or charities using Adobe Commerce to run their online stores or manage customers could be affected. Organisations not using Adobe Commerce are not at risk from this specific issue. If you are unsure whether your website or systems use Adobe Commerce, check with your IT provider or web developer.

4. What to do now

  • Contact your IT provider or software supplier immediately to check if your Adobe Commerce installation is affected.
  • Apply any security updates or patches provided by Adobe as soon as they become available.
  • Review access controls and monitor for unusual account activity on your Adobe Commerce platform.
  • Ensure regular backups of your website and customer data are in place in case recovery is needed.

5. Ask your IT provider

Can you confirm if our Adobe Commerce system is affected by CVE-2026-71362, and have the necessary security patches been applied to prevent privilege escalation attacks?

6. Bottom line

If you use Adobe Commerce, act quickly to secure your system and protect your customers from account takeover risks.

Information based on CISA KEV, NVD, and reputable security news reports.

Back to Vulnerability Briefs