Arbitrary Code Execution Vulnerability in Adobe Commerce
CVE-2026-75650
Key Information:
- Vendor
Adobe
- Vendor
- CVE Published:
- 7 September 2026
Badges
What is CVE-2026-75650?
CVE-2026-75650 is a critical vulnerability affecting Adobe Commerce, a widely used e-commerce platform that allows businesses to create and manage online stores. The vulnerability is categorized as an arbitrary code execution flaw due to an improper neutralization of special elements in its template engine. This vulnerability can be exploited by attackers to execute arbitrary code within the context of the authenticated user, thus potentially compromising the entire application without the need for any user interaction. The implications of this flaw could be substantial as it allows attackers to manipulate the software's functionality, access sensitive data, or take control of the affected environment, significantly endangering organizational operations.
Potential Impact of CVE-2026-75650
-
Unauthorized Access and Control: The ability to execute arbitrary code means that an attacker can gain unauthorized access and control over the affected system, leading to a complete compromise of the application and its data.
-
Data Breaches: This vulnerability can result in the unauthorized retrieval or alteration of sensitive information stored within the Adobe Commerce platform, including customer data, transaction records, and proprietary business information, which could be exploited for malicious purposes.
-
Operational Disruption: Exploitation of this flaw could lead to severe operational disruption, as compromised systems may become unreliable or unresponsive, impacting e-commerce activities and revenue generation for businesses reliant on Adobe Commerce.
CISA has reported CVE-2026-75650
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-75650 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Adobe Commerce 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
Adobe Commerce B2B 0 <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
Magento Open Source 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
This Week In Security: It’s Patch Tuesday Again, TVs Spying, Supply Chain Worms Return, Prolonged Hack Impacts, Stolen IDs
Several times this summer, Microsoft’s Patch Tuesday, the monthly roundup of major security patches for Microsoft products, has included record-breaking numbers of security fixes. The August …
2 weeks ago
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source - IT Security News
2026-09-10 22:09 TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated...
3 weeks ago
ASD warns Aussie Adobe Commerce and Magento stores under attack
Key points A critical vulnerability tracked as CVE-2026-75650, rated 10.0 on the CVSS scale, allows unauthenticated remote code execution on Adobe Commerce and Magento Open Source. Sansec, which discovered...
3 weeks ago
References
CVSS V3.1
Timeline
- 💰
Used in Ransomware
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 🦅
CISA Reported
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved