Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-75650: Adobe Commerce and Magento may run attacker code
CVE-2026-75650 · published 23 days ago · actively exploited
Summary
Both Adobe Commerce and Magento Open Source use a template system that does not properly filter special characters. This weakness could let a hacker insert their own commands and run them on your server. Apply the latest security updates from Adobe to fix the issue.
What to do
- Update adobe commerce to version 2.4.4 or later.
- Update adobe commerce_b2b to version 1.3.3 or later.
- Update adobe magento to version 2.4.6 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | commerce and magento | All versions |
| adobe | adobe commerce | <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug |
| adobe | adobe commerce b2b | <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug |
| adobe | magento open source | <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug |
| adobe | commerce |
< 2.4.4 2.4.4 2.4.5 2.4.6 2.4.7 2.4.8 2.4.9 cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:* |
| adobe | commerce_b2b |
< 1.3.3 1.3.3 1.3.4 1.4.2 1.5.2 1.5.3 cpe:2.3:a:adobe:commerce_b2b:*:-:*:*:*:*:*:* |
| adobe | magento |
< 2.4.6 2.4.6 2.4.7 2.4.8 2.4.9 cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:* |
Original advisory text
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
References
- https://helpx.adobe.com/security/products/magento/apsb26-146.html Patch Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-... US Government Resource
Internet-facing
3 days
and check for signs of compromise
Internal
3 days
and check for signs of compromise
- Known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
4%
chance of attack within 30 days
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published7 Sep 2026
Updated30 Sep 2026
First seen8 Sep 2026
Track software like this
Free during beta