Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-75650: Adobe Commerce and Magento may run attacker code

CVE-2026-75650 · published 23 days ago · actively exploited
Summary

Both Adobe Commerce and Magento Open Source use a template system that does not properly filter special characters. This weakness could let a hacker insert their own commands and run them on your server. Apply the latest security updates from Adobe to fix the issue.

What to do
  • Update adobe commerce to version 2.4.4 or later.
  • Update adobe commerce_b2b to version 1.3.3 or later.
  • Update adobe magento to version 2.4.6 or later.
Affected software
VendorProductAffected versions
adobe commerce and magento All versions
adobe adobe commerce <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
adobe adobe commerce b2b <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
adobe magento open source <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug
adobe commerce < 2.4.4
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*
adobe commerce_b2b < 1.3.3
1.3.3
1.3.4
1.4.2
1.5.2
1.5.3
cpe:2.3:a:adobe:commerce_b2b:*:-:*:*:*:*:*:*
adobe magento < 2.4.6
2.4.6
2.4.7
2.4.8
2.4.9
cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:*
Original advisory text
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
Fix within
Internet-facing 3 days
and check for signs of compromise
Internal 3 days
and check for signs of compromise
  • Known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
4% chance of attack within 30 days
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published7 Sep 2026
Updated30 Sep 2026
First seen8 Sep 2026
Sources
CVE-2026-75650 · MITRE
CVE-2026-75650 · CISA KEV
Track software like this
Free during beta