## Overview
CISA added CVE-2026-75650 to its Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026. This vulnerability affects Adobe Commerce and Magento. It allows for improper neutralization of special elements in a template engine. The flaw can lead to arbitrary code execution without user interaction.
## Technical Details
The vulnerability arises from how Adobe Commerce and Magento handle special elements in their template engines. An attacker can exploit this flaw to execute arbitrary code in the context of the current user. This means that the attacker does not need to rely on social engineering or other forms of user interaction to trigger the exploit. The CVSS score for this vulnerability is 10.0, indicating a critical severity level.
## Impact
Successful exploitation of CVE-2026-75650 could allow attackers to gain full control over affected systems. This could lead to data breaches, unauthorized access, and potential disruption of services. The risk is particularly high for organizations that rely on Adobe Commerce and Magento for e-commerce operations.
## Mitigation
Defenders should prioritize applying patches provided by Adobe for this vulnerability. Organizations should also review their current security posture and ensure that all systems running Adobe Commerce and Magento are updated to the latest versions. Regular vulnerability assessments and monitoring for unusual activity can help mitigate the risks associated with this flaw.
CSURFACE Threat Sensor