DIRAS TAKE
Urgent: CISA placed CVE-2026-75650 on its Known Exploited Vulnerabilities catalog with a rapid remediation due date, and exploit code is publicly available, so prioritize mitigation or removal of internet exposure immediately.
What is CVE-2026-75650?
Remote attackers can execute arbitrary code against Adobe Commerce and Magento Open Source via an improper neutralization bug in the platform's template engine. CVE-2026-75650 allows unauthenticated, network‑accessible attackers to run code in the context of the application without user interaction. Affected releases include Adobe Commerce 2.x and Magento Open Source 2.x builds listed as 2.4.9-2026-aug through earlier, Adobe Commerce B2B 1.x releases 1.5.3-2026-aug through earlier, and other 2.x/1.x releases noted as affected in vendor advisories.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Adobe Commerce and Magento are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Adobe Commerce 2.x | 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug and earlier | |
| Adobe Commerce B2B 1.x | 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug and earlier | |
| Magento Open Source 2.x | 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug and earlier |
Is CVE-2026-75650 being exploited?
CISA added CVE-2026-75650 to the Known Exploited Vulnerabilities catalog on 2026-09-08; US federal agencies must remediate by 2026-09-11. Public exploit code is available.
How to fix CVE-2026-75650
- Apply vendor guidance and mitigations immediately; follow Adobe's instructions if available.
- Remove or restrict internet exposure to affected Adobe Commerce and Magento instances until mitigations are in place.
- Monitor application and web server logs for suspicious template rendering activity and indicators of compromise.
- Follow CISA and organizational patch-prioritization procedures; consider decommissioning vulnerable instances if mitigations are unavailable.
Frequently asked questions
Is CVE-2026-75650 being actively exploited?
CISA added CVE-2026-75650 to its Known Exploited Vulnerabilities catalog on 2026-09-08 and required remediation by 2026-09-11; public exploit code is also available.
Which Adobe Commerce and Magento versions are affected by CVE-2026-75650?
Adobe Commerce 2.x and Magento Open Source 2.x releases listed as 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug and earlier are affected, plus Adobe Commerce B2B 1.x releases listed as 1.5.3-2026-aug and earlier.
Is there a patch for CVE-2026-75650?
No fixed releases are listed in the provided facts; follow Adobe's guidance and apply vendor mitigations when they are published.
Does CVE-2026-75650 require authentication?
No; the vulnerability can be exploited without authentication against network‑accessible Adobe Commerce and Magento instances.
References
- nvd.nist.gov/vuln/detail/CVE-2026-75650
- cve.org/CVERecord?id=CVE-2026-75650
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650
- helpx.adobe.com/security/products/magento/apsb26-146.html
- All Adobe CVEs on CVE Radar
- CVEs published in September 2026