Apply updates to patch critical vulnerability in Adobe Commerce and Magento Open Source
This message is intended for U-M IT staff who are responsible for systems running Adobe Commerce or Magento Open Source.
Summary
Adobe released security updates on Tuesday, August 11, to patch multiple vulnerabilities. This includes a critical vulnerability in Adobe Commerce that allows unauthenticated remote code execution and privilege escalation. Apply the updates as soon as possible after appropriate testing.
The need for immediate action supersedes the remediation timeframes in Vulnerability Management (DS-21).
Problem
Critical vulnerability (CVE-2026-71362) lets an unauthenticated remote attacker switch a customer session to another customer account and escalate privileges without requiring administrator access. Indications have emerged that threat actors are attempting to exploit the vulnerability in the wild.
CVE-2026-71362 is one of seven vulnerabilities that Adobe has addressed.
Threats
Indications have emerged that threat actors are attempting to exploit the critical vulnerability (CVE-2026-71362) in the wild.
Affected Systems
Adobe Commerce, Commerce B2B, and Magento Open Source release lines on all platforms. See the Adobe Security Bulletin for the detailed list.
Action Items
Apply the August 2026 security updates as soon as possible: Latest Product Security Updates.
Website administrators must first ensure they’re running the latest -p release available for their supported release branch before applying the corresponding isolated patch.
Technical Details
Details for each of the seven vulnerabilities:
- CVE-2026-71362 (9.1, critical severity): Incorrect authorization vulnerability that could be leveraged to gain elevated access to sensitive resources without authentication.
- CVE-2026-48414 (7.7, high severity): Stored cross-site scripting vulnerability that could result in arbitrary code execution. Exploitation requires authentication and administrator privileges.
- CVE-2026-48413 (8.7, high severity): Stored cross-site scripting vulnerability that could result in arbitrary code execution. It requires authentication but not administrator privileges.
- CVE-2026-48415 (7.6, high severity): Incorrect-authorization vulnerability affecting Adobe Commerce B2B that could enable a security-feature bypass. It requires authentication but not administrator privileges.
- CVE-2026-48416 (7.5, high severity): Incorrect-authorization vulnerability that could enable a security-feature bypass. It requires neither authentication nor administrator privileges.
- CVE-2026-48411 (6.5, medium severity): Incorrect-authorization vulnerability that could enable a security-feature bypass. Exploitation requires authentication and administrator privileges.
- CVE-2026-48412 (2.7, low severity): Incorrect-authorization vulnerability that could result in privilege escalation. Exploitation requires authentication and administrator privileges.
Questions, Concerns, Reports
Please contact ITS Information Assurance through the ITS Service Center.
References
- Latest Product Security Updates, Adobe Product Security Incident Response Team, 08/11/2026
- Adobe Security Bulletin, 08/11/2026
- Adobe Commerce Bug Targeted Immediately After Disclosure, Security Week, 08/13/2026
- Hackers exploit critical Adobe Commerce flaw to hijack customer accounts, Bleeping Computer, 08/12/2026
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws, The Hacker News, 08/12/2026
- Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws, Security Week, 08/11/2026
- Adobe patches critical Magento account takeover (APSB26-92), Sansec, 08/11/2026