Critical Unauthenticated Account Takeover in Adobe Commerce (CVE‑2026‑71362) Threatens E‑Commerce Customer Data
What It Is — Adobe Commerce (including Commerce B2B and Magento Open Source) contains a critical flaw (CVE‑2026‑71362) that lets an unauthenticated attacker switch a victim’s session to another customer’s account, effectively hijacking the account and exposing private data.
Exploitability — Publicly disclosed on 13 Aug 2026; active exploitation observed within hours. CVSS 9.1 (Critical). No user interaction, no credentials required.
Affected Products — Adobe Commerce, Adobe Commerce B2B, Magento Open Source (all versions prior to the July 2026 patches).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Controls (CC6.1) – The vulnerability demonstrates a gap in logical access and session‑management controls that auditors will scrutinize.
- Continuous Evidence – Prompt patching and proof of remediation become audit artifacts; lacking them can be cited as a control failure.
- Enterprise Buyer Expectations – Large retailers now demand documented SOC 2 compliance; an unpatched session‑hijack flaw can invalidate a vendor’s trust posture.
Recommended Actions
- Apply Adobe’s isolated patch (APSB‑26‑92) immediately across all Commerce instances.
- Verify that session‑handling logic now enforces proper token validation; run a post‑patch security scan.
- Map the fix to SOC 2 CC6.1 (Logical Access Control) and capture patch‑deployment logs as evidence for auditors.
- Enable continuous monitoring for anomalous session activity (e.g., multiple IPs per session) and integrate alerts into your SIEM.
Source: SecurityAffairs – Adobe Commerce CVE‑2026‑71362 Comes Under Attack Shortly After Public Disclosure