Weekly roundup
Open-source business platforms, week 37 of 2026: exploited Adobe Commerce template engine flaw leads 17 fixes
Week 37 of 2026 covers 17 open-source platform CVEs, led by exploited Adobe Commerce template engine flaw CVE-2026-75650 (CVSS 10, in CISA KEV). Patch that first, then the other Adobe Commerce, Dolibarr, TYPO3, WooCommerce and PrestaShop fixes.
The release at a glance
The week 37 roundup covers 17 CVEs in scope across Adobe Commerce (9), Dolibarr (2), TYPO3 CMS (2), Frappe Framework (2), WooCommerce (1) and PrestaShop (1). Severity distribution is 3 critical, 10 high, 3 medium and 1 unscored.
The priority is CVE-2026-75650, an improper neutralization of special elements used in a template engine (CWE-1336) in Adobe Commerce. It has a CVSS 3.1 score of 10 and can lead to arbitrary code execution without user interaction. CISA added it to KEV on 8 September 2026 with a required-action due date of 11 September 2026; CISA SSVC rates exploitation as active, and ENISA EUVD records exploitation since 8 September 2026.
What matters most
The CVEs to look at first are:
Adobe Commerce and Magento Open Source
- CVE-2026-75650 — template engine flaw with CVSS 10, no user interaction, exploited in the wild according to CISA KEV, CISA SSVC and ENISA EUVD. This is the top priority.
- CVE-2026-76201 and CVE-2026-76200 — stored XSS with CVSS 9.3; malicious scripts in form fields can execute in a victim's browser and potentially take over an account or session.
- CVE-2026-77774 — incorrect authorization, CVSS 8.6, network pre-authentication; could give unauthorised read access.
- CVE-2026-77109 — incorrect authorization, CVSS 8.6, network pre-authentication; privilege escalation to restricted resources.
- CVE-2026-76202 — incorrect authorization, CVSS 8.2, network pre-authentication; elevated access to sensitive information.
Dolibarr
- CVE-2026-89013 — authorization bypass, CVSS 8.7; unauthenticated attackers can read arbitrary files through document storage via a crafted hashp parameter, including application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.
TYPO3 CMS
- CVE-2026-85400 — missing authorization in lowlevel commands, CVSS 7.5; backend administrators without system maintainer privileges could schedule configuration:read, configuration:set, and configuration:show commands, potentially gaining system maintainer privileges or causing denial of service. Exploitation requires an administrator-level backend user account.
Patch in this order
- Apply the Adobe hotfix for CVE-2026-75650 to affected Adobe Commerce, Adobe Commerce B2B and Magento Open Source installations. This is the only exploited issue and the only KEV entry; CISA's due date is 11 September 2026.
- Move internet-facing Adobe Commerce, Adobe Commerce B2B and Magento Open Source stores to the September 2026 release line. This closes the stored XSS and incorrect authorization issues in this Adobe Commerce set. Fixed versions include Adobe Commerce 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep and 2.4.4-2026-sep; Adobe Commerce B2B 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep and 1.3.3-2026-sep; and Magento Open Source 2.4.9-2026-sep, 2.4.8-2026-sep and 2.4.7-2026-sep.
- Update Dolibarr to 24.0.1, especially if document storage endpoints are reachable from the internet. This addresses CVE-2026-89013.
- Update WooCommerce to 11.1.0 and TYPO3 CMS to 14.3.7 to address CVE-2026-48888 and CVE-2026-85400 respectively.
- Review the remaining release items: CVE-2026-89012 in Dolibarr, CVE-2026-84186 in PrestaShop, CVE-2026-77132 in TYPO3 CMS, and GHSA-55m4-gj6h-q6rc and GHSA-78c5-55xg-jm7m in Frappe Framework. Apply vendor guidance where applicable.
Beyond the patch
With CVE-2026-75650 exploited in the wild, Managed Detection & Response (MDR) is the first line for detecting and responding to active attempts. For the commerce and ERP platforms themselves, Implementation & Assessment Services can test and harden public-facing shops and the document storage endpoints involved in flaws like CVE-2026-89013.
Every advisory in this release
| ID | Product | Severity | |
|---|---|---|---|
| CVE-2026-75650 | Adobe Commerce | Critical 10.0 KEV | Advisory → |
| CVE-2026-76201 | Adobe Commerce | Critical 9.3 | Advisory → |
| CVE-2026-76200 | Adobe Commerce | Critical 9.3 | Advisory → |
| CVE-2026-89013 | Dolibarr | High 8.7 | Advisory → |
| CVE-2026-77111 | Adobe Commerce | High 8.7 | Advisory → |
| CVE-2026-77774 | Adobe Commerce | High 8.6 | Advisory → |
| CVE-2026-77109 | Adobe Commerce | High 8.6 | Advisory → |
| CVE-2026-76202 | Adobe Commerce | High 8.2 | Advisory → |
| CVE-2026-77110 | Adobe Commerce | High 7.6 | Advisory → |
| CVE-2026-77108 | Adobe Commerce | High 7.5 | Advisory → |
| CVE-2026-48888 | WooCommerce | High 7.5 | |
| CVE-2026-85400 | TYPO3 CMS | High 7.5 | |
| CVE-2026-89012 | Dolibarr | High 7.1 | Advisory → |
| CVE-2026-84186 | PrestaShop | Medium 6.9 | |
| CVE-2026-77132 | TYPO3 CMS | Medium 5.3 | |
| GHSA-55m4-gj6h-q6rc | Frappe Framework | Medium 5.3 | |
| GHSA-78c5-55xg-jm7m | Frappe Framework | Not scored |
References
Vendor advisory
Patch and release notes
Other
CVE
- CVE-2026-75650 — cve.org
- CVE-2026-75650 — NVD
- EUVD-2026-72530 — ENISA EUVD
- CVE-2026-76201 — cve.org
- CVE-2026-76201 — NVD
- EUVD-2026-74036 — ENISA EUVD
- CVE-2026-76200 — cve.org
- CVE-2026-76200 — NVD
- EUVD-2026-74037 — ENISA EUVD
- CVE-2026-89013 — cve.org
- CVE-2026-89013 — NVD
- EUVD-2026-76144 — ENISA EUVD
- CVE-2026-77111 — cve.org
- CVE-2026-77111 — NVD
- EUVD-2026-74030 — ENISA EUVD
- CVE-2026-77774 — cve.org
- CVE-2026-77774 — NVD
- EUVD-2026-74031 — ENISA EUVD
- CVE-2026-77109 — cve.org
- CVE-2026-77109 — NVD
- EUVD-2026-74035 — ENISA EUVD
- CVE-2026-76202 — cve.org
- CVE-2026-76202 — NVD
- EUVD-2026-74032 — ENISA EUVD
- CVE-2026-77110 — cve.org
- CVE-2026-77110 — NVD
- EUVD-2026-74034 — ENISA EUVD
- CVE-2026-77108 — cve.org
- CVE-2026-77108 — NVD
- EUVD-2026-74033 — ENISA EUVD
- CVE-2026-48888 — cve.org
- CVE-2026-48888 — NVD
- EUVD-2026-72651 — ENISA EUVD
- CVE-2026-85400 — cve.org
- CVE-2026-85400 — NVD
- EUVD-2026-72675 — ENISA EUVD