VORANT. Threat Intelligence Sign in Get the full feed

Adobe Commerce zero-day CVE-2026-75650 exploited

severe vulnerability retailtechnology

ANSSI warns of active exploitation of a remote code execution flaw in Adobe Commerce, Magento Open Source, and Commerce B2B.

ANSSI (French CERT) has issued an advisory regarding CVE-2026-75650, a vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows an attacker to achieve remote code execution. Adobe has confirmed that this vulnerability is being actively exploited in the wild, prompting Adobe to release an urgent security bulletin (APSB26-146) on September 7, 2026, describing it as a critical update.

Organizations running affected versions of Adobe Commerce, Commerce B2B, or Magento Open Source without the security patch should apply Adobe's fix immediately given confirmed active exploitation. No further technical details on the exploitation method, indicators of compromise, or threat actor attribution were provided in this advisory; defenders should consult Adobe's bulletin directly for patch guidance and monitor for anomalous activity on e-commerce platforms.

Mentioned in this report

Vulnerabilities CVE-2026-75650KEV

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1130

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free