APSB26-92 Patched a Magento Account Takeover. Don’t Sit on This One.
Adobe’s August bulletin landed on 11 August 2026, four weeks after July. Seven issues. Five of them critical. The one that made us book clients the same week is CVE-2026-71362: an unauthenticated customer account takeover. CVSS 9.1. No login. No admin. No “please click this link.”
People who read the patch say Magento was getting customer identity wrong in the session. In practice, that means an attacker can point an existing session at someone else’s account and walk around as them. Orders. Addresses. Saved payment tokens if you store that kind of thing. The data you promised customers you protect.
The short version
- This is the account-takeover patch. Treat it that way, not as another monthly PDF.
- Adobe shipped isolated patch files, not a fresh Composer package. July has to be on first.
- B2B stores need the B2B August file as well. The core patch does not cover every B2B hole.
If you applied July and stopped, you are still open
Affected means Adobe Commerce or Magento Open Source at 2026-jul or earlier. The matching B2B packages too. “We patched last month” is not a closing statement any more. Adobe’s monthly cadence means each file sits on the one before it.
The rest of APSB26-92 is the usual mix: stored XSS (one a regular customer can trigger) and a few authorization misses. Adobe was not aware of active exploits when they published. We still do not wait on account-takeover bugs. Those get turned into tooling.
Sansec’s note is the clearest public write-up we have seen of the session switch. Adobe’s own bulletin is APSB26-92.
Why August feels fiddlier than July
Isolated patches are faster for Adobe to ship. They are also easier to apply in the wrong order. They are tested against the latest security-only build of your line. Skip July, and August is a coin flip.
Cloud merchants can usually take this through Magento Cloud Patches. Everyone else downloads the zip for the exact line from Adobe’s repo, applies it on staging, then production. If you run B2B, apply that package in the same window. One of the critical authorization issues is tagged B2B on purpose.
What we do after it lands
- Confirm July is present. Then apply the August isolated file for your line.
- Smoke-test customer login, “forgot password,” and a normal order as a logged-in buyer.
- B2B: company account, shared catalog, and a quote if you use them.
- If the store sat unpatched for a while, glance at recent password resets and admin users. You are looking for “that should not be there,” not for a novel.
Questions we keep getting
Can we Composer-update to “2026-aug” and be done?
Not for this one. Adobe released isolated files, not a new Composer security package, for the August fixes. Follow the isolated-patch notes for your line. Cloud is the exception if Magento Cloud Patches already includes it.
Is a customer account takeover as bad as an admin breach?
It is a different kind of bad. The attacker may not get your admin. They can still read another shopper’s orders and personal data, place or change orders, and burn trust in a way that is hard to walk back. For a store, that is enough.
Adobe said no exploits in the wild. Why the urgency?
Because the bug needs no account and no click. That is the profile automated scanners love. “Not exploited on publication day” has been a short-lived sentence on Magento more than once this year.
Need the August isolated patch applied in the right order?
Send us the current version string and whether B2B is in the stack. We will tell you if July is missing, apply August on staging, and only then touch production.
