CVE-2026-75650
Adobe Commerce and Magento Open Source template engine flaw enables unauthenticated code execution (CVE-2026-75650)
CISA KEV lists CVE-2026-75650 as exploited. Adobe Commerce, Adobe Commerce B2B and Magento Open Source have a template engine flaw allowing unauthenticated remote code execution. Apply the relevant hotfix and treat internet-facing instances as exposed.
What happened
Adobe Commerce, Adobe Commerce B2B and Magento Open Source are affected by an improper neutralisation of special elements used in a template engine (CWE-1336). An attacker who can reach the application over the network can exploit the flaw without credentials and without any user interaction, and execute arbitrary code in the context of the current user. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, with a score of 10; the changed scope means the impact can extend beyond the vulnerable component.
CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-75650 as exploited, added on 8 September 2026 with a due date of 11 September 2026. CISA SSVC also rates exploitation as active and automatable.
Who is affected
Adobe Commerce: versions up to and including 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug. Adobe Commerce B2B: versions up to and including 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug and 1.3.3-2026-aug. Magento Open Source: versions up to and including 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug and 2.4.6-2026-aug. Organisations running these platforms as internet-facing storefronts or internal commerce applications should treat themselves as affected.
What to do now
- Apply the relevant hotfix now: Adobe Commerce Hotfix for CVE-2026-7565, Adobe Commerce B2B Hotfix for CVE-2026-7565, or Magento Open Source Hotfix for CVE-2026-7565, depending on the product in use.
- Prioritise any internet-facing instance; the flaw is reachable over the network without authentication and is listed in CISA KEV with a due date of 11 September 2026.
- If patching must be delayed, restrict network exposure to the commerce and admin interfaces and monitor for unexpected code execution. The available record does not list a vendor workaround.
- After applying the hotfix, verify that the affected component is no longer reachable from untrusted networks where possible.
How to detect it
The available record does not provide vendor-specific indicators of compromise. Because this vulnerability is reachable over the network with no credentials, start by inventorying internet-facing Adobe Commerce and Magento Open Source storefront and admin instances; unexpected code execution or changes on those hosts should be investigated.
Beyond the patch
Apply the hotfix first; then put detection and exposure management in place so the next critical commerce flaw is less disruptive. Managed Detection & Response (MDR) is the right fit here because CISA KEV lists it as exploited, and Virtual CISO Services (vCISO) can help identify internet-reachable instances before they are exploited.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Adobe Commerce | – ≤ 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug | Hotfix for CVE-2026-7565 B2B Hotfix for CVE-2026-7565 |
| Adobe Commerce B2B | – ≤ 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug | Hotfix for CVE-2026-7565 |
| Magento Open Source | – ≤ 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug | Hotfix for CVE-2026-7565 |