We have deployed a platform-wide block for the unauthenticated customer account takeover in Adobe Commerce and Magento Open Source disclosed in APSB26-92.
Background
Adobe published an isolated security patch for APSB26-92 on 2026-08-11. The update fixes seven vulnerabilities, five of which are rated Critical. The most severe is CVE-2026-71362, an unauthenticated customer account takeover with a CVSS score of 9.1. Exploitation requires no existing account, no administrator privileges, and no user interaction. An attacker can switch a customer session to another customer account, giving them access to that account and its private customer data.
What we did
We have deployed an Nginx-level rule across all Hypernodes that blocks exploitation attempts before they reach your Magento application. The rule is active on all nodes out of the box.
Note: This block covers the account takeover vector at the platform level. It does not replace the Adobe security patch.
Action required
None for the block. The rule has been applied automatically and requires no action or restart on your part.
We do recommend installing the Adobe patches for APSB26-92, since they also address the remaining fixed vulnerabilities, which include stored cross-site scripting and authorization flaws. Adobe ships these as isolated patch files. Before applying them, make sure you are running the latest -p release for your supported release line. See the Adobe security bulletin for details, or our analysis via the Sansec research on this vulnerability.
- Adobe security bulletin: https://helpx.adobe.com/security/products/magento/apsb26-92.html
- Sansec research: https://sansec.io/research/adobe-commerce-account-takeover-apsb26-92
If you have questions about this vulnerability or your node’s security posture, contact our support team.