# Adobe Commerce zero-day CVE-2026-75650 exploited

Published: 2026-09-08 · Severity: severe · Sectors: retail, technology
Canonical: https://vorant.io/reports/cd0a2645-1721-5f17-a3a2-b265c1436a25/adobe-commerce-zero-day-cve-2026-75650-exploited

> ANSSI warns of active exploitation of a remote code execution flaw in Adobe Commerce, Magento Open Source, and Commerce B2B.

ANSSI (French CERT) has issued an advisory regarding CVE-2026-75650, a vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows an attacker to achieve remote code execution. Adobe has confirmed that this vulnerability is being actively exploited in the wild, prompting Adobe to release an urgent security bulletin (APSB26-146) on September 7, 2026, describing it as a critical update.

Organizations running affected versions of Adobe Commerce, Commerce B2B, or Magento Open Source without the security patch should apply Adobe's fix immediately given confirmed active exploitation. No further technical details on the exploitation method, indicators of compromise, or threat actor attribution were provided in this advisory; defenders should consult Adobe's bulletin directly for patch guidance and monitor for anomalous activity on e-commerce platforms.

## Mentioned in this report

- Vulnerabilities: CVE-2026-75650 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1130

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/cd0a2645-1721-5f17-a3a2-b265c1436a25/adobe-commerce-zero-day-cve-2026-75650-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
