When the Payment-Failure Email Is the Exploit: Inside the Magento Template Rendering Chain of CVE-2026-75650
A vulnerability CVE-2026-75650 with a CVSS score of 10.0 has been found in Adobe Commerce and Magento Open Source, allowing unauthenticated remote code execution via a payment-failure email template. Adobe released an emergency hotfix VULN-39341 on September 7, 2026, and CISA added the vulnerability to its exploited catalog on September 8.
- Vulnerability affects Adobe Commerce 2.4.4–2.4.9 and Magento Open Source 2.4.6–2.4.9
- Attack requires no authentication or user action, CVSS 10.0
- Exploitation began September 4, hotfix released September 7
- Attackers installed a Rust backdoor disguised as system processes and web shells
Read next
Security