Summary
- CVE-2026-75650 affects Adobe Commerce and Magento Open Source and can permit unauthenticated arbitrary code execution.
- Adobe confirms exploitation in the wild and has assigned its highest patch priority.
- The emergency hotfix is distinct from Adobe’s separate September Commerce security release covering other vulnerabilities.
Adobe has released an emergency hotfix for a maximum-severity vulnerability in Adobe Commerce and Magento Open Source after confirming that attackers are exploiting the flaw in the wild.
Adobe disclosed CVE-2026-75650 on 7 September and assigned it a CVSS score of 10.0. The vulnerability involves improper neutralisation of special elements used in a template engine and can allow arbitrary code execution without authentication.
The company rates the hotfix priority one, its highest deployment priority. Affected versions include multiple Adobe Commerce 2.4.x branches, Adobe Commerce B2B releases, and Magento Open Source versions up to their August 2026 builds.
Adobe explicitly states that it is aware of CVE-2026-75650 being exploited in the wild. That moves remediation beyond precaution against a theoretical vulnerability: systems left exposed after the hotfix became available face an attack technique already being used against real environments.
Cyber Insider covered exploitation of the flaw while it remained an active zero-day. Adobe’s hotfix changes the operational position by providing administrators with a supported remediation path.
The emergency bulletin should not be confused with Adobe’s separate September Commerce security release. The monthly bulletin addresses additional vulnerabilities with different severities and exploitation conditions. Applying the monthly update does not remove the need to follow Adobe’s specific instructions for CVE-2026-75650.
Commerce infrastructure presents an attractive attack surface because internet-facing storefronts connect directly to customer transactions and often integrate with payment services, content management, identity platforms, extensions, fulfilment systems, analytics, and back-office applications.
Unauthenticated arbitrary code execution on that layer can therefore give an attacker more than access to a web page. The potential impact depends on the permissions of the affected application, connected services, secrets available to it, and the wider architecture behind the store.
For systems that were online before the hotfix was installed, remediation also needs to distinguish patching from incident assessment. Installing the fix prevents future exploitation of the known flaw; it does not establish that an exposed environment was not compromised beforehand.
Stores operating during the exploitation period may therefore need to examine logs, application integrity, unexpected accounts or files, credentials available to the Commerce environment, and activity in connected systems. The level of investigation should follow the system’s exposure and the evidence available rather than an assumption that patch success proves historic integrity.
The incident also illustrates the availability problem around emergency product-security fixes. E-commerce platforms can be highly customised, tightly integrated, and directly tied to revenue. Rapid changes outside normal maintenance windows carry operational risk, but continuing to expose a known unauthenticated code-execution flaw carries a demonstrably active security risk.
That tension cannot be resolved by CVSS alone. Organisations need to know whether affected versions are internet-facing, how heavily customised they are, which downstream systems trust them, and whether failover or maintenance arrangements allow an urgent change without creating a separate outage.
CVE-2026-75650 now has a vendor fix and confirmed exploitation. The remaining question for individual operators is whether the hotfix arrived before or after attackers reached their systems — and whether their investigation is capable of telling the difference.




