Adobe Commerce / Magento CVE-2026-75650: unauthenticated RCE rated 10/10, already exploited
> In short: CVE-2026-75650 affects Adobe Commerce, Adobe Commerce B2B, and Magento Open Source (versions ≤ 2.4.9-2026-aug for Commerce and Magento Open Source, ≤ 1.5.3-2026-aug for B2B). It's a template-engine injection flaw (CWE-1336), remotely exploitable with no authentication or user interaction required, allowing arbitrary code execution in the context of the current user — with a scope change that opens the door to full takeover of the store and its infrastructure. CVSS score: 10.0, the maximum possible. The flaw is confirmed to be actively exploited in the wild. Adobe released an emergency hotfix ("VULN-39341") on September 7, 2026, in bulletin APSB26-146.
How the exploitation works
The vulnerability allows malicious code to be injected into Magento's template system by exploiting the parser at the style-properties level, bypassing some existing security filters. The documented attack vector runs through failed-payment or error-reporting workflows: an injected payload is stored and later executed when Magento renders certain templated emails — typically failed-payment reminders. Notably, exploitation requires no human to open the email. The code executes server-side at template render time, which explains why stores already patched against previous issues were still hit until the emergency hotfix shipped.
Once code execution was achieved, analysts documented the installation of persistent backdoors and malicious cron jobs, enabling durable access even after a superficial initial cleanup.
Why the 10/10 rating is justified
The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) checks every box of the worst-case scenario: network-exploitable, low attack complexity, no privileges required, no user interaction, changed scope, and maximum impact on confidentiality, integrity, and availability. In practice, an anonymous attacker can, with a single well-formed request, achieve code execution on an e-commerce server potentially holding tens of thousands of orders, customer records, and payment details.
What Adobe Commerce and Magento stores must do
pub/media.The lesson for e-commerce platforms
A 10.0 CVSS score on a widely deployed e-commerce platform is a maximum-alert signal: the combination of "no authentication required" and "arbitrary code execution" turns any unpatched Magento store into a target that can be automated at scale. For companies operating or integrating Adobe Commerce/Magento stores, patch speed after a 9+ rated CVE is no longer a best practice — it's operational survival, especially since active exploitation preceded the public availability of the full fix.
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
Adobe Campaign Classic CVE-2026-48449: a perfect 10.0 RCE in enterprise marketing
A maximum-severity authorization flaw (CVSS 10.0) in Adobe Campaign Classic allows arbitrary code execution without user interaction. Paired with CVE-2026-48448 (SQL injection, 8.6) allowing arbitrary file reads. Fixed in ACC v7 build 9398. Not yet exploited.
N-able N-central CVE-2026-86218: CVSS 10 Pre-Auth RCE Exploited, One Month After August Flaw
A static code injection (CVE-2026-86218, CVSS 10.0) enables pre-authentication remote code execution in N-central, fixed by the September 5 Hotfix 4. N-able confirms active exploitation, CISA lists it in KEV (September 11 deadline), and Huntress investigates a fully patched customer server compromised September 4. Two chainable same-day flaws allow creating a rogue administrator account.
Adobe ColdFusion CVE-2026-48282: a max-severity RCE exploited within 2 hours of disclosure
A maximum-severity flaw (CVSS 9.8) in Adobe ColdFusion 2025.9, 2023.20 and earlier allows unauthenticated remote code execution. Exploitation started within 2 hours of Adobe's disclosure. ~800 instances exposed online. Fix available.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.