Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.

SAP fixes CVE-2026-58231, a CVSS 10.0 Commerce Cloud flaw that could let unauthenticated attackers execute arbitrary code.

Adobe patches seven ColdFusion, Commerce, and Campaign Classic flaws that could enable code execution, privilege escalation, or denial-of-service.