CVE-2026-75650
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.68%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-1336
- Published
- 2026-09-07
- Last modified
- 2026-09-09
Affected products
- Adobe Adobe Commerce
- Adobe Adobe Commerce
- Adobe Adobe Commerce B2B
- Adobe Adobe Commerce B2B
- Adobe Magento Open Source
- Adobe Magento Open Source
Weakness type
Related vulnerabilities
- CVE-2026-87021 — Tanium addressed an unauthorized code execution vulnerability in Comply.
- CVE-2026-33387 — Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0
- CVE-2026-52762 — YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
- CVE-2026-46636 — Twig: Sandbox method allowlist bypass via `Markup` subclass
- CVE-2026-85654 — Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
- CVE-2026-13297 — Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2026-75036 — Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing
- CVE-2026-82958 — In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the...