THREAT OPS › CVEs › CVE-2026-75650
CVE-2026-75650 — Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
Vulnerability details
- Affected productsCommerce and Magento
- KEV remediation due2026-09-11
Related reporting
- CVE-2026-75650: StyleSmuggler — Critical RCE in Adobe Commerce and Magentoakamai_blog
- CISA Adds Four Known Exploited Vulnerabilities to Catalogcisa_advisories
- Microsoft Patch Tuesday, September 2026 Security Update Reviewqualys
- The September 2026 Security Update Reviewzdi_blog
- [CISA KEV] CVE-2026-75650 — Adobe Commerce and Magento: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerabilitycisa_kev
- StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-daytenable
- Adobe security advisory (AV26-888)cccs_ca
- Adobe fixes critical Magento zero-day exploited to backdoor serversbleepingcomputer
- Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shellthehackernews