CVE•Published 2026-09-07•Modified 2026-09-09•2 articles on news•4 live references•NVD data
CVE-2026-75650Adobe · Commerce
Vulnerability data via NVD (ingested)
CVSS v3.1
10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS percentile
50
Exploit Prediction Scoring System · top 50% of all CVEs
Description
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Timeline
Published 2026-09-07
Modified 2026-09-09
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-75650Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Adobe Commerce"All exposed Adobe Commerce instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Commerce"HTTP body or banner mentions "Commerce" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-75650Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-75650Censys host search filtered to this CVE id.
grep.app
CVE-2026-75650Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-75650GitHub code search for direct mentions.
Google dork
"CVE-2026-75650" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (7)
CVE-2026-756507 repos
disrex-group/stylesmuggler-mitigationunknown
Emergency mitigation for StyleSmuggler, the unpatched Magento/Adobe Commerce RCE (Sansec, 2026-09-05). Web-server rules + CLI guard + compromise scanner.
SamJUK/m2-meta-security-patchesShell
Composer meta-package that automatically applies critical and isolated security patches for Magento 2 / Adobe Commerce, released by Adobe
CryptoGenNepal/CVE-KEV-RSSPython
CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild and CryptoGen Nepal aims to simplify this for the general public in a more understan…
dinosn/cve-2026-75650-magento-validation-labShell
Docker lab for validating the CVE-2026-75650 Magento component-level PHP execution primitive and Adobe VULN-39341 patch.
RohitAppadi/CISA-threat-trackerPython
DevGreick/devgreickPython
disrex-group/stylesmuggler-adobe-patchesPHP
composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Magento, via cweagans/composer-patches. Auto-selects the patch for your Magento version.