CISA added CVE-2026-75650, a maximum-severity, unauthenticated code execution bug in Adobe Commerce and Magento Open Source, to the Known Exploited Vulnerabilities catalog on September 8, 2026, with a three-day remediation deadline.
What Is It
CVE-2026-75650 is an improper neutralization of special elements used in a template engine vulnerability (CWE-1336) in Adobe Commerce. Per Adobe's advisory, it can result in arbitrary code execution in the context of the current user, and exploitation does not require user interaction. Scope is changed, meaning impact extends beyond the vulnerable component's security boundary.
Adobe's PSIRT scored it CVSS 3.1 base 10.0 (Critical): vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. That is network-attackable, low complexity, no privileges, no user interaction, with total confidentiality, integrity, and availability impact.
Why It Matters
CISA's KEV listing confirms active exploitation in the wild. The accompanying SSVC decision point data from the CISA Coordinator marks exploitation as active, automatable as yes, and technical impact as total: the worst combination available in that model. Automatable exploitation against internet-facing storefronts means mass scanning and opportunistic compromise are realistic.
The KEV entry lists known ransomware campaign use as Unknown, and flags the vulnerability as requiring forensic triage.
What's Vulnerable
Per Adobe's affected-product data:
- Adobe Commerce: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug and earlier
- Adobe Commerce B2B: 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug and earlier
- Magento Open Source: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug and earlier
NVD's CPE configuration covers Adobe Commerce builds below 2.4.4 as well as the full 2.4.4 patch series (2.4.4 through 2.4.4-p18).
Patch Status
Adobe's advisory APSB26-146 is the authoritative remediation source. Administrators should consult it directly for the fixed builds that apply to their deployment and installation channel, and apply the corresponding update.
CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure. Due date: September 11, 2026.
Sources
- Adobe Security Bulletin APSB26-146; https://helpx.adobe.com/security/products/magento/apsb26-146.html
- NVD, CVE-2026-75650, https://nvd.nist.gov/vuln/detail/CVE-2026-75650
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk