Security Issues

Adobe Commerce Template Engine RCE (CVE-2026-75650): Scope and Emergency Response

Adobe confirmed active exploitation of a pre-authentication remote code execution flaw in Adobe Commerce and Magento Open Source. This guide maps the affected product lines to the dedicated hotfix, credential rotation, and deployment validation steps.

Adobe Commerce CVE-2026-75650 pre-authentication code execution cover
Adobe Commerce CVE-2026-75650 pre-authentication code execution cover

Active exploitation and a pre-authentication path

Adobe published APSB26-146 on September 7, 2026 and confirmed that CVE-2026-75650 has been exploited in the wild. The flaw is an improper neutralization issue in the template engine and can lead to arbitrary code execution without credentials. Protecting only the Admin panel does not close this exposure because the vulnerable processing boundary is reached before authenticated administration.

The response must cover every runtime and deployment source: public storefront nodes, administrative nodes, batch workers, standby systems, staging environments, autoscaling images and disaster-recovery templates. A patched node behind a load balancer does not prove that the whole service is fixed if an older image can later rejoin the pool.

Four stages from an external request through the Adobe Commerce template boundary to code execution
Attack path and impact

Affected product families

The bulletin lists Adobe Commerce branches 2.4.4 through 2.4.9 at the August 2026 level and earlier, supported Commerce B2B branches from 1.3.3 through 1.5.3 at that level and earlier, and Magento Open Source branches 2.4.6 through 2.4.9 at that level and earlier. Inventory must distinguish the base Commerce product, B2B modules and Open Source deployments rather than relying on a single marketing name.

Dedicated VULN-39341 hotfix

Adobe directs affected deployments to the dedicated VULN-39341 Composer hotfix. Obtain it only from the official support path, compare the tested product combinations with the running estate, validate order, cart, payment, tax, shipping, Admin, API, GraphQL and cron workflows in staging, then deploy the same change to every production node and reusable image.

Credential rotation is part of remediation

Adobe also instructs merchants to rotate the Commerce encryption key and the credentials protected or used by the platform. This includes Admin passwords, REST, SOAP and GraphQL integration tokens, OAuth client secrets, payment-gateway credentials, database passwords, SSH and deployment keys, privileged service accounts, and shipping or tax extension keys. Changing the Commerce key alone does not revoke secrets at their external issuers.

Five response stages from identifying Adobe Commerce product lines to validating caches and jobs
Emergency response order

Evidence of completion

Record three forms of evidence: the hotfix artifact and change approval, the applied status on each live or standby node, and functional results from the real service path. Adobe Commerce on Cloud can use the Quality Patches Tool status for VULN-39341. Other deployment models should compare the built artifact with running nodes and prove that newly created instances start from the fixed image.

  1. Classify every Commerce, B2B and Magento Open Source instance.
  2. Validate the dedicated hotfix against business-critical workflows.
  3. Patch every runtime, standby node and deployment image.
  4. Rotate platform and third-party credentials at their issuers.
  5. Verify transactions, integrations, scheduled jobs and security logs.

Sources reviewed

  1. Security update available for Adobe Commerce | APSB26-146Adobe · Official source
  2. Urgent Action Required: Critical Security Update Available for Adobe Commerce (APSB26-146)Adobe Experience League · Official source

SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.

READER COMMENTS

Comments

0

No comments yet.

Do not include personal information, advertising, or contact details.