WHAT HAPPENED
Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data. Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory. The flaw affects Commerce, Commerce B2B and Magento Open Source versions through theJuly 2026 patches. The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY