Skip to main content
QUIETLYTIC
Vulnerability

Adobe Commerce Authentication Bypass (CVE-2026-75650)

CVE-2026-75650 is a maximum-severity CVSS 10 template injection flaw in Adobe Commerce and Magento, added to CISA KEV Sept. 8, 2026 as actively exploited.

CVE-2026-75650
Threat Level
CRITICAL
CVSS
10.0
Status
Active Exploitation
Confidence
Medium
Affected Products
Adobe Commerce, Magento

CVE-2026-75650, a maximum-severity template injection vulnerability in Adobe Commerce and Magento, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026, confirming active exploitation. NVD scores the flaw CVSS 3.1 base 10.0 — the ceiling of the scale — network-exploitable, no privileges or user interaction required.

What the vulnerability does

NVD classifies CVE-2026-75650 under CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). Per NVD’s description, Adobe Commerce is affected by a template-engine injection flaw that “could result in arbitrary code execution in the context of the current user,” with exploitation requiring no user interaction and a changed scope (an attacker-controlled component affecting resources beyond its own security scope).

The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) confirms a network-reachable flaw requiring no authentication and no user interaction, with high impact to confidentiality, integrity, and availability, and a changed scope — consistent with arbitrary code execution against an internet-facing e-commerce platform.

Why it’s on KEV

CISA added CVE-2026-75650 to the KEV catalog on September 8, 2026, which under Binding Operational Directive (BOD) 26-04 requires federal civilian agencies to apply mitigations by CISA’s specified deadline based on the assessed risk. Adobe’s own advisory, APSB26-146 (linked from NVD’s reference data), carries the vendor’s remediation guidance; CISA’s KEV entry directs affected organizations to that guidance and to evaluate each asset’s internet exposure directly rather than publishing a fixed remediation timeline of its own.

What we don’t yet have

FIRST EPSS scores this CVE’s 30-day exploitation probability at 2.1% (81st percentile) — notably low for a KEV-listed, CVSS 10.0 flaw, a gap between theoretical severity and EPSS’s population-relative exploitation-likelihood model worth flagging rather than smoothing over. Beyond that, our data pipeline has not yet corroborated most fields with a second independent source — NVD and CISA KEV agree on the CWE classification, but CVSS scoring, the vulnerability description, and EPSS each currently trace to only one contributing source, so we’re marking overall confidence medium, not high. We also don’t have a specific exploit-availability classification (proof-of-concept vs. weaponized vs. observed-in-the-wild beyond the KEV listing itself) for this CVE.

Why this matters

A maximum-severity, pre-authentication code-execution flaw in a widely deployed e-commerce platform is a high-value target by default — Adobe Commerce and Magento installations routinely process payment data and customer PII, and a successful exploit chain here can hand an attacker code execution on the storefront’s backend. Combined with the KEV listing (meaning CISA has evidence of real-world exploitation, not just theoretical risk), organizations running affected Adobe Commerce or Magento versions should treat this as an immediate patching priority rather than routine maintenance-window work — notwithstanding EPSS’s comparatively low population-level score, which measures near-term probability across all tracked CVEs, not the risk to any specific KEV-confirmed target.

Frequently Asked Questions

What is CVE-2026-75650? A maximum-severity (CVSS 10.0) template injection vulnerability in Adobe Commerce and Magento, tracked under CWE-1336, that can result in arbitrary code execution.

Is CVE-2026-75650 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 8, 2026, which CISA only does when it has evidence of active exploitation.

What should Adobe Commerce/Magento administrators do? Apply Adobe’s fix per advisory APSB26-146 and evaluate internet-facing exposure immediately, consistent with CISA’s BOD 26-04 guidance for KEV-listed vulnerabilities.


Data sourced from the National Vulnerability Database (NVD), CISA’s Known Exploited Vulnerabilities (KEV) catalog, and FIRST’s Exploit Prediction Scoring System (EPSS), aggregated September 10, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog
03 FIRST EPSS

Related intelligence


Analyst tools