The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek.

Exploitation attempts targeting a recently disclosed vulnerability in Adobe Commerce, identified as CVE-2026-71362, were observed almost immediately following the release of patches by Adobe. This rapid move from disclosure to active targeting highlights a recurring challenge in software security, where threat actors quickly weaponize newly public vulnerability information.
The specific technical mechanism of CVE-2026-71362 was not detailed in the report, but its immediate targeting suggests it is a flaw that could be readily understood and exploited by attackers. Vulnerabilities in e-commerce platforms like Adobe Commerce often involve issues such as remote code execution, SQL injection, cross-site scripting, or authentication bypasses. Such flaws can allow attackers to compromise the integrity of online stores, steal customer data, or inject malicious code, leading to significant financial and reputational damage.
Adobe Commerce, formerly known as Magento, is a widely used e-commerce platform, particularly popular among medium to large businesses. Its extensive feature set and customizability also present a broad attack surface. Given its role in processing sensitive customer and transaction data, any vulnerability in Adobe Commerce is of significant concern.
The likely scope of impact for such a vulnerability, if exploited, could range from individual compromised stores to broader campaigns targeting multiple instances of the platform. Attackers often scan the internet for unpatched systems, and the window between patch release and widespread application is a prime opportunity for them.
Typical mitigation guidance for this class of issue emphasizes the importance of timely patching. Organizations using Adobe Commerce are strongly advised to apply security updates as soon as they become available. Beyond patching, other best practices include implementing robust web application firewalls (WAFs), regularly auditing security configurations, employing strong access controls, and conducting routine security assessments and penetration testing.
This incident underscores the critical importance of a rapid response to security disclosures. The observed immediate targeting of CVE-2026-71362 after its disclosure and the availability of patches illustrates the "race to patch" scenario that organizations face. Threat actors are increasingly sophisticated and automated in their ability to identify and exploit newly public vulnerabilities, making prompt patching and continuous security vigilance indispensable for protecting online assets.

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.