Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-75650 2026-09-08

Adobe Commerce Template Engine Flaw Hits CVSS 10.0, Lands in CISA KEV

"CISA added CVE-2026-75650, a maximum-severity, unauthenticated code execution bug in Adobe Commerce and Magento Open Source, to the Known Exploited Vulnerabilities catalog on September 8, 2026, with a three-day…"

CISA added CVE-2026-75650, a maximum-severity, unauthenticated code execution bug in Adobe Commerce and Magento Open Source, to the Known Exploited Vulnerabilities catalog on September 8, 2026, with a three-day remediation deadline.

What Is It

CVE-2026-75650 is an improper neutralization of special elements used in a template engine vulnerability (CWE-1336) in Adobe Commerce. Per Adobe's advisory, it can result in arbitrary code execution in the context of the current user, and exploitation does not require user interaction. Scope is changed, meaning impact extends beyond the vulnerable component's security boundary.

Adobe's PSIRT scored it CVSS 3.1 base 10.0 (Critical): vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. That is network-attackable, low complexity, no privileges, no user interaction, with total confidentiality, integrity, and availability impact.

Why It Matters

CISA's KEV listing confirms active exploitation in the wild. The accompanying SSVC decision point data from the CISA Coordinator marks exploitation as active, automatable as yes, and technical impact as total: the worst combination available in that model. Automatable exploitation against internet-facing storefronts means mass scanning and opportunistic compromise are realistic.

The KEV entry lists known ransomware campaign use as Unknown, and flags the vulnerability as requiring forensic triage.

What's Vulnerable

Per Adobe's affected-product data:

NVD's CPE configuration covers Adobe Commerce builds below 2.4.4 as well as the full 2.4.4 patch series (2.4.4 through 2.4.4-p18).

Patch Status

Adobe's advisory APSB26-146 is the authoritative remediation source. Administrators should consult it directly for the fixed builds that apply to their deployment and installation channel, and apply the corresponding update.

CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure. Due date: September 11, 2026.

Sources