CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Summary
A critical vulnerability exists in Adobe Commerce and Magento Open Source where improper neutralization of special elements in a template engine could lead to arbitrary code execution. Adobe is providing mitigations, and CISA is urging adherence to its security update prioritization guidance.
IFF Assessment
The vulnerability allows for arbitrary code execution, which is a severe security risk for defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 11, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in widely used e-commerce platforms poses a significant risk of code execution, potentially leading to ransomware or data breaches. Defenders must prioritize applying vendor-provided mitigations and comply with CISA's guidance for prioritizing security updates based on risk.