# Adobe Commerce Is Under Active Attack — Again. This Time They're Coming for Customer Accounts.
Patch logs don't lie. When Adobe pushed an emergency fix for CVE-2026-71362 last week, the severity rating was critical and the advisory language was careful — "potential for account compromise." Security researchers watching honeypots weren't surprised. By the time the patch dropped, exploitation attempts were already in the wild.
The vulnerability sits in Adobe Commerce and Magento's authentication handling and allows attackers to hijack customer accounts without knowing the target's password. That's the short version. The implications for any merchant still running an unpatched storefront are worse than the advisory language suggests.
## What "Account Hijacking" Actually Means on a Commerce Platform
On a social media app, account takeover is bad. On an e-commerce platform, it's a direct path to fraud at scale.
A hijacked Adobe Commerce account typically contains: stored shipping addresses, saved payment methods (or tokenized card references), full order history, and — for wholesale merchants or B2B portals — credit lines and negotiated pricing. Attackers who successfully exploit CVE-2026-71362 don't just get a username and password. They get a shopping cart funded by someone else.
The mechanics of this specific flaw haven't been fully disclosed, which is standard responsible disclosure practice while patches propagate. What's been confirmed: the exploit doesn't require authentication to initiate, which places it in the category of unauthenticated pre-auth takeovers — the class that moves fastest in the wild because no social engineering is required. There's no phishing email, no malicious attachment. An attacker hits an endpoint, and if the target merchant is unpatched, they're in.
## Magento's Long History as a High-Value Target
Adobe Commerce — still widely called Magento by practitioners who remember when it was independent — has been under sustained attack from organized threat groups for the better part of a decade. The reason isn't mysterious: e-commerce platforms process card data, store customer PII, and sit at the intersection of high transaction volume and operators who are often small-to-medium businesses without dedicated security staff.
Magecart, the loosely affiliated constellation of threat groups that pioneered web skimming, built an entire criminal economy on Magento's attack surface. The playbook was simple: exploit a vulnerability to gain access, inject a few lines of JavaScript into checkout pages, harvest card data for months before detection. The British Airways breach in 2018, which cost the carrier £20 million in ICO fines alone, used this technique. Ticketmaster, Newegg, hundreds of smaller merchants — all hit with variants of the same skimmer methodology.
Last year's CosmicSting vulnerability (CVE-2024-34102) was a direct ancestor of the current situation. That flaw — also critical, also unauthenticated — allowed XML External Entity injection that exposed encryption keys. Researchers observed active exploitation within days of disclosure. Thousands of merchants were compromised before they patched, and some of those compromises persisted for months as attackers used the stolen keys to maintain access even after the underlying vulnerability was closed.
CVE-2026-71362 is a different technical class of vulnerability, but the ecosystem dynamics are identical. The merchant base is slow to patch. The attack tooling gets commoditized quickly. The window between "publicly known" and "widely exploited" is measured in hours, not weeks.
## Who's Actually Running Unpatched Adobe Commerce Right Now
Magento has a well-documented patch adoption problem. A 2023 survey by security firm Sansec found that a substantial portion of Magento installations were running versions years behind the current release. The reasons are predictable: custom extensions that break on upgrades, third-party themes with compatibility issues, development shops that deployed and walked away, merchants who don't know what version they're running.
Adobe Commerce's enterprise tier fares better — those deployments typically have managed hosting or SI partners maintaining them. The vulnerable tail is in the Magento Open Source community, where a merchant who launched a store in 2021 with a customized theme may have never applied a major security patch.
That's the population attackers are hunting. They're not targeting the Shopify-scale deployments; they're scanning for the long tail of small and medium merchants who built on Magento because it was free, customizable, and powerful — and who are now running unpatched software with real customer data sitting in the database.
## What Defenders Should Do Right Now
If you run Adobe Commerce or Magento Open Source, the priority list is short:
Immediate:
Within the week:
Merchants running managed Magento hosting through Adobe Commerce Cloud should verify patch status directly — don't assume your hosting provider has handled it without confirmation.
---
## HackWire Analysis
The pattern here should feel familiar to anyone who's followed Magento security over the past decade, and that familiarity is itself the problem.
Every major Magento/Adobe Commerce critical vulnerability follows the same arc: disclosure, patch, slow merchant adoption, active exploitation, eventual compromise notifications. The security community has known about the platform's patch velocity problem for years. Adobe has improved its disclosure process and patch communication. None of that has meaningfully changed how quickly the median merchant applies a critical update.
CVE-2026-71362 is notable because account hijacking — as opposed to direct payment skimming — shifts the threat model in a way merchants may not have planned for. Traditional Magecart defense focused on checkout integrity: subresource integrity checks, CSP headers, server-side monitoring for unexpected JavaScript. Account takeover bypasses all of that. An attacker who hijacks 500 customer accounts and slowly works through stored payment methods looks, from the server's perspective, like legitimate customer activity. Detection requires behavioral analytics and anomaly detection on authentication patterns, not just endpoint monitoring.
This also raises a regulatory exposure question that's getting insufficient attention: if an attacker exploits CVE-2026-71362 and makes fraudulent purchases using hijacked accounts, who bears the fraud cost? Payment processors and card networks have been sharpening their chargeback liability rules around merchant security posture. A merchant who knew about a critical vulnerability and failed to patch within a reasonable window may find their fraud liability claims scrutinized. The breach is bad; the chargeback dispute is worse.
The broader lesson — and one that Adobe Commerce merchants should genuinely internalize — is that running an e-commerce platform in 2026 means treating security patching as a core business operation, not an IT task that happens when convenient. The threat actors scanning for CVE-2026-71362 are automated, fast, and indiscriminate. They'll find your storefront before your quarterly review cycle catches the advisory.
— HackWire Editorial
---
## Related Coverage