CyberzSOC

Publication detail
← Back to advisories & guidance

CRITICAL ALERT: Active exploitation of Adobe Commerce and Magento Open Source vulnerability ↗ source

September 9, 2026 ASD/ACSC Alert

Summary

ASD’s ACSC is aware of a substantial number of potentially vulnerable instances within the Australian economy and encourage system owners to follow the mitigation advice from the vendor. This alert is relevant to all Australian organisations that utilise Adobe Commerce and Magento Open Source. Adobe Commerce and Magento Open Source are PHP-based e-commerce platforms used to power online storefronts. CVE-2026-75650 is an Improper Neutralisation of Special Elements Used in a Template Engine vulnerability, leading to unauthenticated remote code execution. If using an unpatched version, organisations should update their version that includes this patch as a priority.

News Coverage

DateSourceArticle
2026-09-08 BleepingComputer Adobe fixes critical Magento zero-day exploited to backdoor servers CVE-2026-75650
2026-09-08 The Hacker News Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell CVE-2026-75650

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-75650 10.0 Critical Adobe Commerce and Magento Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allo…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.