Critical RCE Vulnerability CVE-2026-75650 Actively Exploited in Adobe Commerce
A critical remote code execution vulnerability, CVE-2026-75650, has been identified in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, with Adobe confirming active in-the-wild exploitation. India's CERT-In rated the flaw CRITICAL under advisory CIVN-2026-0458, published on September 16, 2026, referencing Adobe security bulletins apsb26-138 and apsb26-146. The flaw allows an unauthenticated remote attacker to execute arbitrary code on affected servers across multiple version branches of all three platforms. Administrators are advised to immediately inventory all deployments, apply vendor patches in a staged manner, and verify the fix on every node, not just primary servers. Since exploitation is already underway, previously exposed hosts should also be inspected for signs of compromise, including unauthorized account changes, file modifications, and suspicious outbound network traffic.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in