ADOBE released an emergency hotfix for a critical vulnerability (CVE-2026-75650) affecting Adobe Commerce and Magento on September 7, 2026. This flaw, with a CVSS score of 10.0, allows unauthenticated attackers to execute arbitrary code and has been confirmed to be exploited in the wild. Key points of the vulnerability include:
- **Affected Versions**: Adobe Commerce versions ≤ 2.4.9-2026-aug and B2B versions 1.3.3-1.5.3 are impacted.
- **Impact**: The exploit can lead to server takeover, exposing sensitive customer data and payment flows without requiring user interaction.
- **Attack Method**: The attack relies on a template-engine injection vulnerability (CWE-1336) allowing code to be executed through the rendering of failed-payment emails.
- **Recommendation**: Users should immediately apply Adobe's hotfix and scan for compromises as earlier patched systems were still vulnerable.