Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3241 articles · 211225 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-75650KEVEXPLOITEDPATCHED
adobe · adobe commerce

Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

Description

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Affected Products

VendorProductVersions
adobeadobe commerce0, 0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
adobemagentocert_advisory90%

References

  • https://helpx.adobe.com/security/products/magento/apsb26-146.html(vendor-advisory)

Related News (6 articles)

Tier B
CCCS Canada1h ago
Adobe security advisory (AV26-888)
→ No new info (linked only)
Tier B
BSI Advisories4h ago
[NEU] [kritisch] Adobe Magento Open Source: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
→ No new info (linked only)
Tier D
CSO Online4h ago
Adobe Commerce max-severity bug comes under active attack
→ No new info (linked only)
Tier D
The Hacker News6h ago
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
→ No new info (linked only)
Tier B
CERT-FR15h ago
Vulnérabilité dans les produits Adobe (08 septembre 2026)
→ No new info (linked only)
Tier C
VulDB19h ago
CVE-2026-75650 | Adobe Commerce/Commerce B2B/Magento Open Source Template Engine neutralization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
Hotfix for CVE-2026-7565
CWECWE-1336
PublishedSep 7, 2026
Trending Score141🔥
Source articles6
Independent6
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-83959
Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
Trending: 17
HIGHCVE-2026-83961
ColdFusion | Improper Authentication (CWE-287)
Trending: 17
HIGHCVE-2026-48388
Photoshop Installer | CWE-427: Uncontrolled Search Path Element
Trending: 15
CRITICALCVE-2026-76197
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Trending: 13
CRITICALCVE-2026-76195
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Trending: 13

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 7, 2026
Added to CISA KEV
Sep 7, 2026
Discovered by ZDM
Sep 7, 2026
Actively Exploited
Sep 8, 2026
Patch Available
Sep 8, 2026