Adobe security advisory (AV26-888)
Canada's Cyber Centre warns CVE-2026-75650 in Adobe Commerce and Magento Open Source is exploited in the wild; hotfixes and updates are available.
Canadian Centre for Cyber Security advisory AV26-888 (September 8, 2026) covers CVE-2026-75650 in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Adobe states the vulnerability is being exploited in the wild. Affected versions extend through the August 2026 patch levels across the 2.4.4-2.4.9 branches, with B2B versions 1.3.x-1.5.x also affected. Administrators are urged to apply the available hotfixes and updates.
- CVE-2026-75650 is exploited in the wild according to Adobe
- Affects Adobe Commerce, Adobe Commerce B2B and Magento Open Source prior to August 2026 hotfix levels
- CCC advisory AV26-888 urges users and administrators to apply available updates
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-7565 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, 4.1.4 via the 'import-user-file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. NVD description · AI analysis pending | 4.9 | <1% |
| — | ||
| CVE-2026-75650 | Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CVE-2026-75650) Adobe Commerce and Magento (including Adobe Commerce B2B) contain an improper neutralization of special elements used in a template engine (CWE-1336), a template-injection flaw that permits arbitrary code execution in the context of the current user. The flaw is reachable over the network by unauthenticated attackers, requires no user interaction, and its changed scope (CVSS 3.1 S:C) means injected code executes beyond the vulnerable component, producing a maximum-severity (CVSS 10.0) remote code execution condition. A successful attacker gains arbitrary code execution on the storefront server; in the observed campaign, intruders installed a Rust backdoor and a PHP web shell (dubbed 'StyleSmuggler') on compromised servers. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is in scope, with internet-facing e-commerce deployments most exposed. Exploitation is confirmed in the wild: the bug was abused as a zero-day before patching and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08. Do: Apply Adobe's released patches immediately per vendor instructions, prioritizing internet-facing Commerce/Magento storefronts, and ensure compliance with CISA BOD 26-04 timelines for KEV entries. Hunt for 'StyleSmuggler' indicators of compromise, including unexpected Rust backdoor binaries and PHP web shells on hosts, and review template/theme customizations for tampering. Exact fixed version numbers are not included in the available data, so consult Adobe's advisory for the correct patched release for your Commerce/Magento version line. | 10.0 | 2% | KEV PoC |
| massroughly 100,000-300,000 internet-facing storefronts |
Full article112 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-888
Date: September 8, 2026
As of September 8, 2026, Adobe is affected by a vulnerability in the following products:
- Adobe Acrobat
- Multiple versions
- Adobe Animate 2023
- Prior to or equal to 2023.0.16
- Adobe Animate 2024
- Prior to or equal to 0.14
- Adobe Campaign Classic
- Prior to or equal to ACC v7: 7.4.4 build 9401
- Adobe ColdFusion 2023
- Prior to or equal to 2023.0.23
- Adobe ColdFusion 2025
- Prior to or equal to 0.12
- Adobe Commerce
- All except Hotfix for CVE-2026-7565
- Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
- Adobe Commerce B2B
- All except Hotfix for CVE-2026-7565
- Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
- Adobe Experience Manager (AEM)
- Prior to or equal to AEM Cloud Service (CS) Release 2026.7.0
- Prior to or equal to 5 LTS Service Pack 2
- Prior to or equal to 5 Service Pack 24 and earlier
- Adobe Illustrator 2025
- Prior to or equal to 8.10
- Adobe Illustrator 2026
- Prior to or equal to 7
- Adobe Photoshop 2025
- Prior to or equal to 11.6
- Adobe Photoshop 2026
- Prior to or equal to 6
- Magento Open Source
- All except Hotfix for CVE-2026-7565
- Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug
Adobe indicates that CVE-2026-75650 is exploited in the wild.
Update 1
On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-75650 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-888