Our takeCSA Singapore and BleepingComputer report active exploitation of CVE-2026-71362 in Adobe Commerce/Magento, letting attackers hijack customer accounts. Patch immediately if you run it.Cyber Resilience desk
What this means for you — Security leader:Patch Adobe Commerce / Magento instances to the latest version immediately. The flaw (CVE-2026-71362) is under confirmed active exploitation and allows account takeover.
What this means for you — Lean IT orgs:If you run your own Adobe Commerce or Magento store, update it right now. Attackers are already using this flaw to take over customer accounts.
What this means for you — MSP:Check every client running Adobe Commerce, Magento, or Adobe Commerce B2B and confirm they are patched past CVE-2026-71362. Exploitation is active in the wild.
What this means for you — Researcher:CVE-2026-71362 in Adobe Commerce/Magento is under confirmed active exploitation per CSA Singapore. Patch priority is high for any internet-facing instance.