Adobe Commerce and Magento CVE-2026-75650: unauthenticated RCE under active exploitation
Published 09 Sep 2026 · Severity: critical
Adobe published APSB26-146 on 7 September 2026 for CVE-2026-75650, a CVSS 10.0 template-engine flaw that permits unauthenticated arbitrary code execution in affected Adobe Commerce and Magento Open Source installations. Adobe confirms exploitation in the wild. Apply the version-specific VULN-39341 hotfix, verify that it is applied, then rotate the Commerce encryption key and every credential or token that may have been protected by it. CISA added the CVE to KEV on 8 September and marks forensic triage as required for assets in its directive scope.