chiprook
← Security
SecuritySeptember 19, 2026, 06:20

When the Payment-Failure Email Is the Exploit: Inside the Magento Template Rendering Chain of CVE-2026-75650

A vulnerability CVE-2026-75650 with a CVSS score of 10.0 has been found in Adobe Commerce and Magento Open Source, allowing unauthenticated remote code execution via a payment-failure email template. Adobe released an emergency hotfix VULN-39341 on September 7, 2026, and CISA added the vulnerability to its exploited catalog on September 8.

When the Payment-Failure Email Is the Exploit: Inside the Magento Template Rendering Chain of CVE-2026-75650
#Adobe#Magento#CISA
Read next
Security

Kaspersky uncovers malware campaign spread via movie torrents

Security

Z.ai silently uploaded devs' local data: 313MB and 564 upload attempts

Security

Samsung and LG to remove botnet apps from smart TV stores

Security

CrowdSec confirms source code stolen in supply chain attack