CVE-2026-75650
published 2026-09-07CVE-2026-75650: Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code…
PriorityP193critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-09-11
Exploited in the wild
EPSS
2.15%
81.0th percentile
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Affected
188 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_commerce | <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug | — |
| adobe | adobe_commerce_b2b | <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug | — |
| adobe | commerce | < 2.4.4 | 2.4.4 |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Commerce/Commerce B2B/Magento Open Source Template Engine neutralization
vuldb·2026-09-07·CVSS 10.0
CVE-2026-75650 [CRITICAL] Adobe Commerce/Commerce B2B/Magento Open Source Template Engine neutralization
A vulnerability, which was classified as critical, has been found in Adobe Commerce, Commerce B2B and Magento Open Source. Affected is an unknown function of the component Template Engine. This manipulation causes improper neutralization.
This vulnerability appears as CVE-2026-75650. The attack may be initiated remotely. There is no available exploit.
GHSA
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user.
ghsa_unreviewed·2026-09-07
CVE-2026-75650 [CRITICAL] CWE-1336 Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user.
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
VulnCheck
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
vulncheck·2026·CVSS 10.0
CVE-2026-75650 [CRITICAL] CWE-1336 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
Affected: Adobe Commerce and Magento
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuri
CISA
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
cisa·2026-09-08·CVSS 10.0
CVE-2026-75650 [CRITICAL] CWE-1336 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Vulnerability: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Affected: Adobe Commerce and Magento
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet expos
No detection rules found.
No public exploits indexed.
Tenable
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
blogs_tenable·2026-09-08·CVSS 7.8
CVE-2026-81963 [HIGH] Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
## Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
104 Critical
860 Important
0 Moderate
0 Low
Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.
Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.
This month’s update includes patches for:
.NET
.NET and Visual Studio
ASP.NET Core
Active Directory Certificate Services (AD CS)
Active Directory Domain Services
Active Directory Federation Services (AD FS)
Audio Video Control Transport Protocol
Azure Arc
Azure CycleCloud
Azure HDInsights
BranchCache
Connected Devices Platform
Tenable
Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”
blogs_tenable·2026-09-08
CVE-2026-81963 Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”
## Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”
Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks.
## Key takeaways
Claude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for research and evaluation, Tenable will now incorporate it within Tenable One, giving defenders access to frontier cyber reasoning to tackle complex exposure management challenges.
Tenable One Adversary View is the first i
Tenable
StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
blogs_tenable·2026-09-08·CVSS 10.0
CVE-2026-75650 [CRITICAL] StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
## StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.
## Key takeaways
CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.
Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different attack campaigns.
Adobe released Hotfix VULN-39341 on September 7, 2026, and Tenable dete
Hackernews
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
blogs_hackernews·2026-09-08·CVSS 10.0
CVE-2026-75650 [CRITICAL] Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.
The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.
"This update resolves a critical vulnerability that could result in arbitrary code execution," Adobe said , adding it's "aware that CVE-2026-75650 has been exploited in the wild targeting A
Qualys
Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
blogs_qualys·2026-09-08
CVE-2026-75650 Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for September2026
Adobe Patch for September 2026
Zero-day Vulnerabilities Patched inSeptemberPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inSeptemberPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Qualys Monthly Webinar Series
Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats.
This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security fla
2026-09-07
Published
2026-09-08
Added to CISA KEV
Exploited in the wild