ZeroDayAlert

CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

Adobe Commerce and Magento Added to KEV 2026-09-08 Federal due 2026-09-11 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

You are affected if you operate Adobe Commerce or Magento Open Source. The vulnerability allows arbitrary code execution through improper handling of template engine syntax, so any deployment accessible to untrusted input — including customer-facing storefronts, admin panels behind weak authentication, or development environments connected to production data — is at risk. The record does not specify which versions of Commerce or Magento Open Source are vulnerable.

How to check whether this touches you

  • Inventory your applications: search your estate for any running instance of Adobe Commerce or Magento Open Source, including development and staging deployments.
  • Check reachability: confirm whether each instance is exposed to the internet or to users outside your organisation who might craft malicious template input.
  • Query the running version: access the application's version information via the admin panel, configuration files, or HTTP headers; note that version numbers alone do not prove patch status, as security updates are sometimes backported.
  • Inspect logs for template injection patterns: search web server and application logs for requests containing template syntax (such as {{, {%, or Twig directives) in user input fields, query strings, or file uploads.

What to do

  1. Immediately: isolate or restrict access to any instance you cannot patch within the federal remediation window (2026-09-11). Apply network-level controls — WAF rules, IP whitelisting, or VPN requirement — to limit who can reach the application.
  2. Apply the vendor patch: follow Adobe's published mitigation instructions as soon as they are available. Prioritise this work under CISA BOD 26-04 guidance.
  3. If patching is unavailable or delayed: escalate to your risk and compliance team to evaluate whether discontinuing use of the product is feasible for your business.
  4. Enable logging: ensure web server access logs and application logs capture HTTP headers, user input, and template rendering errors; retain logs for at least 90 days to support forensics.
  5. Plan forensic review: prepare to search logs and file integrity records backwards from the present day for evidence of exploitation, since active attacks often precede public disclosure.

If you find you were exposed

Check your logs and file-change records for evidence of code execution: look for unexpected file modifications, new user accounts, suspicious process execution, or outbound connections from the web server. Search backwards at least to the CVE publication date, but preferably further if your log retention allows. Document the earliest sign of compromise and preserve logs before any cleanup, as they will be needed for incident response and potential investigation by authorities.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-75650 is being exploited. It cannot tell you whether Commerce and Magento is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →