What is CVE-2026-75650?
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Timeline
- 2026-09-07Published to the U.S. National Vulnerability Database (NVD)
- 2026-09-08Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-09-09NVD record last updated
- 2026-09-11CISA federal remediation deadline (BOD 22-01)
CISA Known Exploited Vulnerability
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Affected product
Adobe Commerce And Magento
NVD also lists CPE entries for: Adobe Commerce, Adobe Commerce B2b, Adobe Magento
Remediation Steps
- Consult CISA's Known Exploited Vulnerabilities catalog for full product and version details.
- Identify affected systems in your environment.
- Obtain and apply the vendor's security patch.
- Verify remediation through testing.
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 1 of September 2026 (September 7 – 13)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.