CVE-2026-75650: Adobe Commerce and Magento
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
- Vendor
- Adobe
- Product
- Commerce and Magento
- Vulnerability
- Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- Date added
- Sep 8, 2026
- CISA due date (U.S. federal agencies)
- Sep 11, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-1336
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02