{"id":2813,"date":"2026-08-13T02:56:41","date_gmt":"2026-08-13T09:56:41","guid":{"rendered":"https:\/\/www.cycognito.com\/blog\/?p=2813"},"modified":"2026-08-13T02:56:43","modified_gmt":"2026-08-13T09:56:43","slug":"emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw","status":"publish","type":"post","link":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/","title":{"rendered":"Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"628\" src=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38-1280x628.png\" alt=\"\" class=\"wp-image-2814\" srcset=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38-1280x628.png 1280w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38-512x251.png 512w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38-768x377.png 768w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38.png 1487w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><figcaption class=\"wp-element-caption\"><em>Sample of assets impacted by Adobe account takeover vulnerability, identified by the CyCognito Platform<\/em><\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What is CVE-2026-71362?<\/h2>\n\n\n\n<p>CVE-2026-71362 is an incorrect authorization vulnerability (CWE-863) in Adobe Commerce and Magento Open Source, caused by the platform failing to correctly bind a customer identity to an account session. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical).<\/p>\n\n\n\n<p>Exploitation requires no authentication. Adobe&#8217;s advisory states that the flaw is exploitable without credentials, does not require administrator privileges, and does not require user interaction. The only precondition is network access to the storefront, which is public by design for the assets that run this software.<\/p>\n\n\n\n<p>Adobe categorizes the impact as privilege escalation. Analysis of the patch by eCommerce security firm Sansec found the underlying problem to be improper handling of customer identity within an account session, which in practice allows an attacker to switch an active session to a different customer account. The attacker then holds that customer&#8217;s authenticated context, including access to stored personal data and order history.<\/p>\n\n\n\n<p>Exploit status is worth stating precisely, because the two available sources differ. Adobe&#8217;s bulletin says the vendor is not aware of exploits in the wild for any issue in the release. Sansec reports that its Shield web application firewall is already blocking exploitation attempts against this CVE. Defenders should plan on the assumption that attack traffic exists.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What assets are affected by CVE-2026-71362?<\/h2>\n\n\n\n<p>The affected software is Adobe Commerce release lines 2.4.4 through 2.4.9 and Magento Open Source release lines 2.4.6 through 2.4.9, at the <code>-2026-jul<\/code> build and earlier in each line. Adobe Commerce B2B versions 1.3.3 through 1.5.3 received fixes in the same bulletin, though CVE-2026-71362 is not flagged as B2B specific.<\/p>\n\n\n\n<p>In practice, an affected asset is a public web storefront served over HTTPS. The population is wider than the primary commerce domain, however. The same codebase typically runs on staging, preproduction, UAT, and developer hosts that are reachable from the internet but excluded from production change control. Admin panels, webmail hosts, and control panel ports on shared hosting frequently sit on the same infrastructure and appear in the same fingerprint.<\/p>\n\n\n\n<p>These assets tend to be overlooked for structural reasons rather than negligent ones. Commerce estates sprawl across brands, regions, product launches, and campaign microsites, and a large share of them are built and hosted by external agencies. A store built for a single campaign keeps serving traffic on an unpatched build long after the campaign owner has moved on, and the security team responsible for the estate often has no inventory record that the store exists.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What does our data show about exposure patterns?<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"750\" src=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-251.png\" alt=\"\" class=\"wp-image-2815\" srcset=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-251.png 1200w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-251-512x320.png 512w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-251-768x480.png 768w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n\n\n\n<p>Exposure in this set is led by Communication Services at 34.5% of observed assets, with Consumer Discretionary contributing 19.6% and Information Technology 14.4%. Assets in this set were identified by software fingerprint, so they represent hosts observed running the affected platform rather than builds confirmed to be at a vulnerable patch level.<\/p>\n\n\n\n<p>The Communication Services concentration reflects how media and entertainment groups actually operate commerce. A single publishing or broadcast group runs merchandise stores for individual titles, ticketing and licensing shops, and promotional storefronts tied to specific releases. Each of those is a separate deployment, often commissioned from a different agency on a different hosting contract, and each carries its own patch cadence. The result is a large estate of small stores rather than one well-governed platform.<\/p>\n\n\n\n<p>Across the remaining sectors the pattern points to the same underlying driver. Commerce is rarely a core function for a manufacturer, a hardware vendor, or an industrial group, so the storefront ends up owned by marketing or by a business unit rather than by central IT. That ownership gap is what produces the long tail of non-production hosts, forgotten campaign sites, and stores that continue serving traffic on a build nobody is tracking. The vulnerability is in the software, but the exposure is a consequence of where the software sits in the org chart.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Are fixes available?<\/h2>\n\n\n\n<p>Yes. Adobe published bulletin APSB26-92 on August 11, 2026, with fixed builds in the <code>-2026-aug<\/code> release for each supported line: Adobe Commerce 2.4.4 through 2.4.9, Magento Open Source 2.4.6 through 2.4.9, and Adobe Commerce B2B 1.3.3 through 1.5.3. Adobe assigned the update a Priority 2 rating.<\/p>\n\n\n\n<p>Patch availability does not mean patch simplicity in this case. According to Sansec, Adobe distributes these monthly fixes as isolated patch files rather than as a new security release or updated Composer packages. A store must already be running the latest <code>-p<\/code> release available for its supported branch before the corresponding isolated patch will apply. Estates that have fallen behind on point releases therefore face a two-step remediation, and the interim window is longer than the advisory date suggests.<\/p>\n\n\n\n<p>Defenders should also note the divergence between Adobe&#8217;s statement that it is not aware of in-the-wild exploitation and third-party WAF telemetry indicating blocked exploitation attempts. Verify patch level and exploit exposure directly against your own hosts and your vendor rather than treating the advisory&#8217;s exploitation status as current.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Are there any other recommended actions to take?<\/h2>\n\n\n\n<p>Recommended mitigations:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Inventory all Adobe Commerce and Magento hosts, including staging and campaign sites<\/li>\n\n\n\n<li>Deploy WAF coverage for storefront customer and session endpoints<\/li>\n\n\n\n<li>Invalidate active customer sessions once the fix is in place<\/li>\n\n\n\n<li>Monitor storefront logs for unexpected account or session switching<\/li>\n\n\n\n<li>Scan previously exposed stores for backdoors added before remediation<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">How can CyCognito help your organization?<\/h2>\n\n\n\n<p>CyCognito published an Emerging Threat Advisory for CVE-2026-71362 in the CyCognito platform and is actively researching enhanced detection capabilities for this vulnerability.<\/p>\n\n\n\n<p>To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, <a href=\"https:\/\/www.cycognito.com\/demo\/\">contact us to request a demo<\/a>.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An incorrect authorization flaw in Adobe Commerce and Magento Open Source lets an unauthenticated attacker switch a customer session to another account, exposing the victim&#8217;s personal data.<\/p>\n","protected":false},"author":39,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[250],"tags":[],"class_list":["post-2813","post","type-post","status-publish","format-standard","hentry","category-emerging-threats"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw | CyCognito Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw | CyCognito Blog\" \/>\n<meta property=\"og:description\" content=\"An incorrect authorization flaw in Adobe Commerce and Magento Open Source lets an unauthenticated attacker switch a customer session to another account, exposing the victim&#039;s personal data.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/\" \/>\n<meta property=\"og:site_name\" content=\"CyCognito Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-13T09:56:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-13T09:56:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1487\" \/>\n\t<meta property=\"og:image:height\" content=\"729\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Igal Zeifman\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Igal Zeifman\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/\"},\"author\":{\"name\":\"Igal Zeifman\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3\"},\"headline\":\"Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw\",\"datePublished\":\"2026-08-13T09:56:41+00:00\",\"dateModified\":\"2026-08-13T09:56:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/\"},\"wordCount\":945,\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38-1280x628.png\",\"articleSection\":[\"Emerging Threats\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/\",\"name\":\"Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw | CyCognito Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38-1280x628.png\",\"datePublished\":\"2026-08-13T09:56:41+00:00\",\"dateModified\":\"2026-08-13T09:56:43+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#primaryimage\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38.png\",\"width\":1487,\"height\":729},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cycognito.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"name\":\"Cycognito Blog\",\"description\":\"Research, Product News and Latest Updates\",\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\",\"name\":\"Cycognito\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"width\":1720,\"height\":550,\"caption\":\"Cycognito\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3\",\"name\":\"Igal Zeifman\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g\",\"caption\":\"Igal Zeifman\"},\"description\":\"VP of Marketing\",\"url\":\"https:\/\/www.cycognito.com\/blog\/author\/igal-zeifman\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw | CyCognito Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/","og_locale":"en_US","og_type":"article","og_title":"Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw | CyCognito Blog","og_description":"An incorrect authorization flaw in Adobe Commerce and Magento Open Source lets an unauthenticated attacker switch a customer session to another account, exposing the victim's personal data.","og_url":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/","og_site_name":"CyCognito Blog","article_published_time":"2026-08-13T09:56:41+00:00","article_modified_time":"2026-08-13T09:56:43+00:00","og_image":[{"width":1487,"height":729,"url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38.png","type":"image\/png"}],"author":"Igal Zeifman","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Igal Zeifman","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#article","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/"},"author":{"name":"Igal Zeifman","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3"},"headline":"Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw","datePublished":"2026-08-13T09:56:41+00:00","dateModified":"2026-08-13T09:56:43+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/"},"wordCount":945,"publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38-1280x628.png","articleSection":["Emerging Threats"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/","url":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/","name":"Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw | CyCognito Blog","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#primaryimage"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38-1280x628.png","datePublished":"2026-08-13T09:56:41+00:00","dateModified":"2026-08-13T09:56:43+00:00","breadcrumb":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#primaryimage","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/2026-08-13_12h54_38.png","width":1487,"height":729},{"@type":"BreadcrumbList","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-71362-adobe-commerce-account-takeover-via-session-identity-flaw\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cycognito.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw"}]},{"@type":"WebSite","@id":"https:\/\/www.cycognito.com\/blog\/#website","url":"https:\/\/www.cycognito.com\/blog\/","name":"Cycognito Blog","description":"Research, Product News and Latest Updates","publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cycognito.com\/blog\/#organization","name":"Cycognito","url":"https:\/\/www.cycognito.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","width":1720,"height":550,"caption":"Cycognito"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3","name":"Igal Zeifman","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g","caption":"Igal Zeifman"},"description":"VP of Marketing","url":"https:\/\/www.cycognito.com\/blog\/author\/igal-zeifman\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2813","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/users\/39"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/comments?post=2813"}],"version-history":[{"count":1,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2813\/revisions"}],"predecessor-version":[{"id":2816,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2813\/revisions\/2816"}],"wp:attachment":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/media?parent=2813"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/categories?post=2813"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/tags?post=2813"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}