Vulnerability record · CVE-2026-75650 · published 7 September 2026
CVE-2026-75650: Adobe Commerce template engine flaw allows unauthenticated remote code execution
Adobe · Commerce
Adobe Commerce, Commerce B2B and Magento are affected by improper neutralization of special elements used in a template engine (CWE-1336), allowing arbitrary code execution in the context of the current user. The flaw is network reachable with no privileges or user interaction required, and the changed scope means impact can extend beyond the vulnerable component. It was added to CISA KEV one day after publication, so treat it as actively exploited.
Description
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a CVSS score of 10, changed scope, and confirmed exploitation per CISA KEV.
What it is
Adobe Commerce, Commerce B2B and Magento are affected by improper neutralization of special elements used in a template engine (CWE-1336), allowing arbitrary code execution in the context of the current user. The flaw is network reachable with no privileges or user interaction required, and the changed scope means impact can extend beyond the vulnerable component. It was added to CISA KEV one day after publication, so treat it as actively exploited.
Impact
An attacker can execute arbitrary code on the affected Commerce or Magento instance, potentially taking full control of the application and its data. Because scope is changed, compromise may extend to other components or the underlying host.
Attack surface
Reached over the network via the template engine processing path, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required, so any internet-exposed instance is directly reachable.
Exploitation
Listed in CISA KEV with a remediation due date of 2026-09-11, indicating known exploitation in the wild; no ransomware campaign use is recorded. EPSS 30-day probability is 0.02148 (81st percentile), which is moderate and secondary to the KEV signal.
What to do
- Apply the vendor patch from Adobe security bulletin apsb26-146 immediately, prioritizing internet-facing Commerce, Commerce B2B and Magento instances.
- If patching cannot be completed within the CISA due date, apply the vendor mitigations or take the instance offline per BOD 26-04 guidance.
- Restrict network access to admin and storefront template-handling endpoints where operationally possible, and block untrusted traffic at the edge.
- Review custom templates, themes and modules for untrusted input reaching the template engine, and remove or sandbox such paths.
- Rotate credentials and secrets stored on or reachable from affected instances after remediation, in case of prior compromise.
Detection
- Hunt web and application logs for template rendering errors, unexpected template file writes, or requests to template-handling endpoints from unusual source IPs.
- Monitor for new or modified files under theme, template and media directories, and for unexpected child processes spawned by the web server or PHP runtime.
- Alert on outbound connections from Commerce or Magento hosts to unfamiliar destinations, which may indicate post-exploitation activity.
- Review authentication and admin activity logs for anomalous sessions or configuration changes around the KEV addition window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-75650 to the Known Exploited Vulnerabilities catalog on 8 September 2026 as "Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 11 September 2026.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/magento/apsb26-146.html | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650 | US Government Resource |
Track CVE-2026-75650 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-75650), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.