Skip to content

Weekly roundup

Open-source business platforms, week 37 of 2026: exploited Adobe Commerce template engine flaw leads 17 fixes

Critical 10.0 KEV Vendor: Open-source business platforms 17 advisories in scope Published

Week 37 of 2026 covers 17 open-source platform CVEs, led by exploited Adobe Commerce template engine flaw CVE-2026-75650 (CVSS 10, in CISA KEV). Patch that first, then the other Adobe Commerce, Dolibarr, TYPO3, WooCommerce and PrestaShop fixes.

The release at a glance

The week 37 roundup covers 17 CVEs in scope across Adobe Commerce (9), Dolibarr (2), TYPO3 CMS (2), Frappe Framework (2), WooCommerce (1) and PrestaShop (1). Severity distribution is 3 critical, 10 high, 3 medium and 1 unscored.

The priority is CVE-2026-75650, an improper neutralization of special elements used in a template engine (CWE-1336) in Adobe Commerce. It has a CVSS 3.1 score of 10 and can lead to arbitrary code execution without user interaction. CISA added it to KEV on 8 September 2026 with a required-action due date of 11 September 2026; CISA SSVC rates exploitation as active, and ENISA EUVD records exploitation since 8 September 2026.

What matters most

The CVEs to look at first are:

Adobe Commerce and Magento Open Source

  • CVE-2026-75650 — template engine flaw with CVSS 10, no user interaction, exploited in the wild according to CISA KEV, CISA SSVC and ENISA EUVD. This is the top priority.
  • CVE-2026-76201 and CVE-2026-76200 — stored XSS with CVSS 9.3; malicious scripts in form fields can execute in a victim's browser and potentially take over an account or session.
  • CVE-2026-77774 — incorrect authorization, CVSS 8.6, network pre-authentication; could give unauthorised read access.
  • CVE-2026-77109 — incorrect authorization, CVSS 8.6, network pre-authentication; privilege escalation to restricted resources.
  • CVE-2026-76202 — incorrect authorization, CVSS 8.2, network pre-authentication; elevated access to sensitive information.

Dolibarr

  • CVE-2026-89013 — authorization bypass, CVSS 8.7; unauthenticated attackers can read arbitrary files through document storage via a crafted hashp parameter, including application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.

TYPO3 CMS

  • CVE-2026-85400 — missing authorization in lowlevel commands, CVSS 7.5; backend administrators without system maintainer privileges could schedule configuration:read, configuration:set, and configuration:show commands, potentially gaining system maintainer privileges or causing denial of service. Exploitation requires an administrator-level backend user account.

Patch in this order

  1. Apply the Adobe hotfix for CVE-2026-75650 to affected Adobe Commerce, Adobe Commerce B2B and Magento Open Source installations. This is the only exploited issue and the only KEV entry; CISA's due date is 11 September 2026.
  2. Move internet-facing Adobe Commerce, Adobe Commerce B2B and Magento Open Source stores to the September 2026 release line. This closes the stored XSS and incorrect authorization issues in this Adobe Commerce set. Fixed versions include Adobe Commerce 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep and 2.4.4-2026-sep; Adobe Commerce B2B 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep and 1.3.3-2026-sep; and Magento Open Source 2.4.9-2026-sep, 2.4.8-2026-sep and 2.4.7-2026-sep.
  3. Update Dolibarr to 24.0.1, especially if document storage endpoints are reachable from the internet. This addresses CVE-2026-89013.
  4. Update WooCommerce to 11.1.0 and TYPO3 CMS to 14.3.7 to address CVE-2026-48888 and CVE-2026-85400 respectively.
  5. Review the remaining release items: CVE-2026-89012 in Dolibarr, CVE-2026-84186 in PrestaShop, CVE-2026-77132 in TYPO3 CMS, and GHSA-55m4-gj6h-q6rc and GHSA-78c5-55xg-jm7m in Frappe Framework. Apply vendor guidance where applicable.

Beyond the patch

With CVE-2026-75650 exploited in the wild, Managed Detection & Response (MDR) is the first line for detecting and responding to active attempts. For the commerce and ERP platforms themselves, Implementation & Assessment Services can test and harden public-facing shops and the document storage endpoints involved in flaws like CVE-2026-89013.

Every advisory in this release

IDProductSeverity
CVE-2026-75650Adobe CommerceCritical 10.0 KEVAdvisory →
CVE-2026-76201Adobe CommerceCritical 9.3Advisory →
CVE-2026-76200Adobe CommerceCritical 9.3Advisory →
CVE-2026-89013DolibarrHigh 8.7Advisory →
CVE-2026-77111Adobe CommerceHigh 8.7Advisory →
CVE-2026-77774Adobe CommerceHigh 8.6Advisory →
CVE-2026-77109Adobe CommerceHigh 8.6Advisory →
CVE-2026-76202Adobe CommerceHigh 8.2Advisory →
CVE-2026-77110Adobe CommerceHigh 7.6Advisory →
CVE-2026-77108Adobe CommerceHigh 7.5Advisory →
CVE-2026-48888WooCommerceHigh 7.5
CVE-2026-85400TYPO3 CMSHigh 7.5
CVE-2026-89012DolibarrHigh 7.1Advisory →
CVE-2026-84186PrestaShopMedium 6.9
CVE-2026-77132TYPO3 CMSMedium 5.3
GHSA-55m4-gj6h-q6rcFrappe FrameworkMedium 5.3
GHSA-78c5-55xg-jm7mFrappe FrameworkNot scored

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them. Entries marked GHSA have no CVE: their source is the security advisory the maintainers published in their official GitHub repository.

Written with AI assistance from the sources above and checked automatically against them before publication.