CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-75650
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-75650Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 81% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-75650 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploited[UPDATE] [kritisch] Adobe Magento Open Source: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode …cert-bund
- highexploited[NEU] [hoch] Adobe Magento: Mehrere Schwachstellencert-bund
- unknownexploitedAdobe Monthly Security Update (September 2026)hkcert
- unknownexploitedAdobe security advisory (AV26-888) – Update 1cccs
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- unknownexploitedNCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magentoncsc-nl
- unknownexploitedVulnérabilité dans les produits Adobe (08 septembre 2026)cert-fr-avis
- criticalexploitedCVE-2026-75650: Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Templat…nvd
Recent advisories for Adobe Commerce and
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commercencsc-nl · 2026-09-09
- highCVE-2026-77774: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd · 2026-09-08
- highCVE-2026-77111: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd · 2026-09-08
- highCVE-2026-77110: Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory (…nvd · 2026-09-08
- highCVE-2026-77109: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in pr…nvd · 2026-09-08
- highCVE-2026-77108: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in pr…nvd · 2026-09-08
More from CISA Known Exploited Vulnerabilities
- criticalCVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability2026-09-09
- criticalCVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability2026-09-09
- criticalCVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vuln…2026-09-09
- criticalCVE-2026-87491: Google Chromium V8 Out of Bounds Write Vulnerability2026-09-09
- criticalCVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability2026-09-08