Adobe Commerce zero-day CVE-2026-75650 exploited
ANSSI warns of active exploitation of a remote code execution flaw in Adobe Commerce, Magento Open Source, and Commerce B2B.
ANSSI (French CERT) has issued an advisory regarding CVE-2026-75650, a vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows an attacker to achieve remote code execution. Adobe has confirmed that this vulnerability is being actively exploited in the wild, prompting Adobe to release an urgent security bulletin (APSB26-146) on September 7, 2026, describing it as a critical update.
Organizations running affected versions of Adobe Commerce, Commerce B2B, or Magento Open Source without the security patch should apply Adobe's fix immediately given confirmed active exploitation. No further technical details on the exploitation method, indicators of compromise, or threat actor attribution were provided in this advisory; defenders should consult Adobe's bulletin directly for patch guidance and monitor for anomalous activity on e-commerce platforms.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1130
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free