๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Summary
Adobe Commerce and Magento Open Source have a vulnerability in their template engine (the system that generates web pages by combining code and data) that fails to properly filter special characters, allowing attackers to execute arbitrary code (run any commands they want on the server). This vulnerability is currently being actively exploited by real attackers.
Solution / Mitigation
"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk guidance." Stakeholders should "evaluate each asset's internet exposure and ensure adherence to BOD 26-04 patching guidelines." For cloud services, follow BOD 26-04 guidance or "discontinue use of the product if mitigations are unavailable." Refer to Adobe's security bulletin at https://helpx.adobe.com/security/products/magento/apsb26-146.html for specific vendor instructions.
Vulnerability Details
EPSS: 0.7%
Yes
๐ฅ Actively Exploited
September 7, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75650
First tracked: September 8, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%