Active Exploitation of Vulnerability in Adobe Products
9 September 2026
Attackers are exploiting a critical vulnerability in Adobe Commerce, Adobe Commerce B2B and Adobe Magento to execute arbitrary code. Patch immediately.
Background
Adobe has released security updates to address a critical vulnerability (CVE-2026-75650) affecting Adobe Commerce and Adobe Magento. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 10.0 out of 10.
Impact
Due to improper neutralisation of special elements used in a template engine in Adobe Commerce, an attacker could execute arbitrary code in the context of the current user, without requiring user interaction.
Known Exploitation
This vulnerability is reportedly being actively exploited.
Affected Products
The vulnerability affects the following products:
- Adobe Commerce versions before 2.4.4, and versions 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8 and 2.4.9
- Adobe Commerce B2B versions before 1.3.3, and versions 1.3.3, 1.3.4, 1.4.2, 1.5.2 and 1.5.3
- Adobe Magento versions before 2.4.6, and versions 2.4.6, 2.4.7, 2.4.8 and 2.4.9
Users and administrators should refer to the vendor advisory for the full list of affected versions.
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
- https://helpx.adobe.com/security/products/magento/apsb26-146.html (opens in new tab)
- https://nvd.nist.gov/vuln/detail/CVE-2026-75650 (opens in new tab)
