CVE-2026-75650 in Magento: 132,792 Matches and a 10.0 CVSS
CISA added CVE-2026-75650, a template engine flaw in Adobe Commerce and Magento Open Source rated CVSS 3.1 10.0, to its Known Exploited Vulnerabilities catalog on 8 September 2026 with a 11 September due date. A ZoomEye query for app="Magento" returned 132,792 matches, while app="Adobe Commerce" returned zero.
- CVE-2026-75650 is a template engine flaw in Adobe Commerce and Magento Open Source with CVSS 10.0
- CISA added it to the KEV catalog on 8 September 2026 with an 11 September deadline
- ZoomEye: app="Magento" returns 132,792 matches, app="Adobe Commerce" returns zero
- Patches are in Adobe bulletin APSB26-146; themes and extensions need separate auditing
Read next
Security