CVE-2026-75650: critical RCE in Adobe Commerce and Magento exploited in the wild
CERT-In warned of a critical flaw, CVE-2026-75650, in Adobe Commerce, Commerce B2B and Magento Open Source that lets an unauthenticated remote attacker execute arbitrary code, with exploitation confirmed in the wild. Fixes are in Adobe bulletins apsb26-138 and apsb26-146.
- Affects Adobe Commerce 2.4.4–2.4.9-2026-aug and Magento Open Source 2.4.6–2.4.9-2026-aug
- The RCE needs no authentication and no user interaction
- Adobe confirmed active exploitation in the wild
- A ZoomEye search found 132,158 hosts with the Magento fingerprint
Read next
Security