Updated 20 Aug 2026: Material correction to exposure assessment: Sansec reported blocking CVE-2026-71362 exploitation attempts immediately after disclosure, while Adobe’s bulletin (last updated Aug. 18) still says it is unaware of in-the-wild exploits. Proposal adds the conflicting evidence, strengthens patch urgency, and distinguishes attempted exploitation from confirmed compromise.

Key details

  1. Adobe published APSB26-92 on August 11, 2026; its bulletin was last updated August 18.
  2. CVE-2026-71362 is an incorrect-authorization flaw rated CVSS 9.1 and requires neither authentication nor admin privileges, according to Adobe.
  3. Adobe says it is not aware of exploits in the wild for the issues fixed by APSB26-92.
  4. Sansec says its Shield WAF is already blocking exploitation attempts against CVE-2026-71362.
  5. Sansec’s patch analysis says the flaw can switch a customer session to another customer account and expose private customer data.
  6. Affected Adobe Commerce release lines include 2.4.4 through 2.4.9; Magento Open Source fixes are provided for supported 2.4.6 through 2.4.9 lines.
  7. Adobe provides August `-2026-aug` updated versions and matching isolated patches, with monthly isolated patches applied in sequence on the required prior baseline.
  8. Adobe’s Commerce Version Tool can report installed and missing monthly patches and CVE coverage.

What builders should take away

  1. Treat CVE-2026-71362 as an urgent internet-facing patch, because independent telemetry indicates exploitation attempts are already occurring.
  2. Do not use Adobe’s current 'not aware of exploits in the wild' statement as a reason to defer remediation; it conflicts with Sansec’s observed attack telemetry.
  3. Before applying an isolated patch, confirm the store is on the required security-only baseline and that prior monthly isolated patches have been applied in sequence.
  4. Use the Commerce Version Tool after remediation to verify actual monthly patch and CVE coverage rather than inferring security state from the base application version.
  5. For Adobe Commerce Cloud, confirm whether the installed Cloud Patches package already contains APSB26-92 before layering an isolated patch, to avoid duplicate-application problems.
  6. Review authentication and customer-account telemetry for suspicious session behavior around the disclosure window, while recognizing that the public evidence establishes attempts rather than confirmed successful compromise.

What changed

The August 2026 security patch itself has not changed, but the exposure assessment needs a material correction. Adobe’s APSB26-92 bulletin, last updated August 18, still says Adobe is not aware of exploits in the wild. Separately, ecommerce security firm Sansec reported on August 11 that its Shield WAF was already blocking exploitation attempts against CVE-2026-71362 after reviewing the patch and confirming that the flaw can switch a customer session to another customer account. The conflicting evidence means operators should not treat Adobe’s vendor statement as evidence that exploitation has not begun.

Why it matters

CVE-2026-71362 is not only remotely reachable without authentication; independent telemetry indicates attackers are already attempting to use it. That moves the risk from a hypothetical critical flaw to an actively probed account-takeover path, increasing the cost of patch delay for internet-facing stores. Sansec’s report describes blocked attempts rather than confirmed successful compromises, so the evidence should be read as active exploitation activity, not proof that every vulnerable store has been breached.

Independent telemetry conflicts with Adobe’s exploit-status statement

Adobe’s bulletin says it is not aware of exploits in the wild for the vulnerabilities fixed by APSB26-92. Sansec, however, says its Shield WAF is already blocking exploitation attempts against CVE-2026-71362. The two statements can coexist if Adobe has not independently confirmed the activity, but builders should base operational urgency on the stronger exposure signal rather than assume the flaw is unused.

The critical flaw can switch a customer session

Sansec says its patch analysis confirmed that CVE-2026-71362 lets an unauthenticated attacker switch a customer session to another customer account, exposing the victim’s account and private customer data. Adobe rates the incorrect-authorization issue CVSS 9.1 and says exploitation requires neither authentication nor administrative privileges.

The remediation path is unchanged

Merchants still need the August 2026 security level or the matching isolated patch for their supported release line. Adobe’s monthly isolated patches are non-cumulative, so the required prior patch baseline must be present before the August fix is applied. Adobe Commerce Cloud users should verify whether their current Cloud Patches package already contains APSB26-92 fixes before applying an isolated patch separately.

What to watch next

  • Whether Adobe revises APSB26-92 to acknowledge exploitation activity or changes its priority guidance.
  • Whether Sansec or other researchers publish broader telemetry showing successful compromise, attack scale or reliable indicators of compromise.
  • Whether public exploit tooling materially lowers the barrier to exploiting CVE-2026-71362.
  • Whether Adobe changes the isolated-patch or Cloud Patches guidance for APSB26-92.

Still unclear

  • Sansec reports that its WAF is blocking exploitation attempts, but the public report does not establish how widespread the activity is or how many attacks succeeded.
  • Adobe’s bulletin, last updated August 18, still says it is unaware of exploitation in the wild, creating a vendor-versus-independent-telemetry discrepancy rather than a settled shared assessment.

Sources

Direct reading behind this dossier.

3 sources