Skip to content

Data collected

CVEs Live

CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Adobe · Commerce and Magento

Listed by CISA as exploited in the wild since 8 Sep 2026. Below: exploitation status, EPSS and every published CVSS, each with its source, then affected versions and references.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

Description

as written by CISA (KEV catalog)

Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

Required action

CISA KEV

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected products and versions

CVE record · adobe

  • Adobe · Adobe Commerce

    • affected: through 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
    • unaffected: Hotfix for CVE-2026-7565
  • Adobe · Adobe Commerce B2B

    • affected: through 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
    • unaffected: Hotfix for CVE-2026-7565
  • Adobe · Magento Open Source

    • affected: through 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug
    • unaffected: Hotfix for CVE-2026-7565

Status words (affected, unaffected, unknown) and version bounds are copied from the record. An upper bound such as “before 7.1.0” usually marks the first fixed version; confirm in the vendor advisory before planning an upgrade.

References

CISA KEV notes and CVE record

EPSS over the last 30 days

See also: all Adobe entries in KEV · the full KEV catalog

Questions about CVE-2026-75650

Is CVE-2026-75650 being exploited?

Yes, according to CISA. CVE-2026-75650 was added to the Known Exploited Vulnerabilities catalog on 8 Sep 2026, which CISA does only with reliable evidence of exploitation in the wild. The catalog field for ransomware campaign use says "Unknown".

What is the deadline to remediate CVE-2026-75650?

CISA set 11 Sep 2026 as the due date for US Federal Civilian Executive Branch agencies. The date is binding only for those agencies; other organisations can read it as a measure of urgency.

What is the EPSS score of CVE-2026-75650?

3.95%, in the 90th percentile, in the FIRST EPSS model of 2 Oct 2026. It estimates the probability of exploitation activity in the following 30 days. For a CVE already in KEV the score is secondary: exploitation has been observed.

How severe is CVE-2026-75650?

adobe.com rates it 10.0 CRITICAL (CVSS 3.1). These are the published assessments as of 3 Oct 2026; this site does not rescore.

Which product does CVE-2026-75650 affect?

Adobe Commerce and Magento, as named in the CISA catalog. The affected versions listed in the CVE record are on this page; the vendor advisory in the references is the authority on fixed versions.

Related sections