CISA added CVE-2026-75650 to its Known Exploited Vulnerabilities (KEV) catalogue on 8 September 2026. The vulnerability affects Adobe Commerce and Magento Open Source and involves improper neutralisation of special elements in a template engine, potentially allowing arbitrary code execution.
The flaw is a template-engine injection vulnerability. Successful exploitation could enable an attacker to execute arbitrary code, but the available data does not specify the attack vector or required privileges. NVD assigns the vulnerability a CVSS score of 10.0 (Critical). Patch availability is currently unknown. Adobe’s security advisory is provided in the KEV entry.
CISA’s inclusion confirms that attackers are actively exploiting the vulnerability. The available entry does not identify use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the issue by 11 September 2026.
CISA requires organisations to apply mitigations in accordance with vendor instructions and comply with BOD 26-04, “Prioritizing Security Updates Based on Risk”, and the “Forensics Triage Requirements”. Agencies must follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset’s internet exposure and follow BOD 26-04 patching guidance. All organisations should review their Adobe Commerce and Magento exposure and take appropriate action.
See the NVD entry and CISA KEV catalogue for full details.