CVE-2026-75650
10.0Adobe · Adobe Commerce
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
Executive summary
A critical remote code execution vulnerability in Adobe Commerce allows unauthenticated attackers to compromise affected systems entirely.
Vulnerability
The flaw is an improper neutralization of special elements used in a template engine (CWE-1336). An unauthenticated attacker can trigger this vulnerability remotely without any user interaction to achieve arbitrary code execution.
Business impact
This vulnerability carries a CVSS score of 10.0, indicating the highest possible severity. Successful exploitation grants an attacker full control over the application server, leading to potential data exfiltration, total system compromise, and significant reputational damage. Given the lack of required authentication or user interaction, this flaw poses an immediate and severe threat to business continuity.
Remediation
Immediate Action: Apply the vendor-provided hotfix for CVE-2026-7565 as detailed in Adobe Security Bulletin APSB26-146.
Proactive Monitoring: Review web server and application logs for suspicious inbound HTTP requests containing template-related syntax or unexpected system calls.
Compensating Controls: Implement a Web Application Firewall (WAF) with strict rules to filter malicious payloads targeting the template engine, although this should be treated only as a temporary measure until the patch is applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical severity and the potential for unauthenticated remote code execution, organizations must prioritize the application of the official Adobe hotfix immediately. Failure to patch this vulnerability leaves the infrastructure exposed to total compromise by external actors. Ensure all affected instances, including B2B and Magento Open Source deployments, are brought up to the corrected version levels without delay.
More Adobe CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section