VDB

CVE-2026-75650

CVE-2026-75650 PUBLISHED CVSS 10 CRITICAL

Reported by adobe · Published September 7, 2026

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Risk Scores

CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
AdobeAdobe Commerce0, Hotfix for CVE-2026-7565
AdobeAdobe Commerce B2B0, Hotfix for CVE-2026-7565
AdobeMagento Open Source0, Hotfix for CVE-2026-7565
AdobeAdobe Commerce B2B0, Hotfix for CVE-2026-7565
AdobeMagento Open Source0, Hotfix for CVE-2026-7565
AdobeAdobe Commerce0, Hotfix for CVE-2026-7565

Timeline

  • Sep 7, 2026 VulnCheck KEV Exploitation
  • Sep 7, 2026 CVE Published

References

  • vendor-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›