Adobe security advisory (AV26-888)
Canada's Cyber Centre warns CVE-2026-75650 in Adobe Commerce and Magento Open Source is exploited in the wild; hotfixes and updates are available.
Canadian Centre for Cyber Security advisory AV26-888 (September 8, 2026) covers CVE-2026-75650 in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Adobe states the vulnerability is being exploited in the wild. Affected versions extend through the August 2026 patch levels across the 2.4.4-2.4.9 branches, with B2B versions 1.3.x-1.5.x also affected. Administrators are urged to apply the available hotfixes and updates.
Adobe patches critical Magento account takeover (APSB26-92)
Adobe ships isolated patches (APSB26-92) for Adobe Commerce and Magento Open Source fixing seven flaws, five Critical including account takeover CVE-2026-71362.
Adobe released isolated security patches under APSB26-92 for Adobe Commerce and Magento Open Source addressing seven vulnerabilities, five of them rated Critical. The critical set includes CVE-2026-71362, which Sansec characterizes as enabling account takeover. Merchots running Magento-based stores are urged to apply the patches.
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog
CISA added four actively exploited flaws to its KEV catalog: Magento StyleSmuggler RCE, two Windows privilege-escalation bugs, and N-able N-central RCE.
CISA added CVE-2026-75650 (Adobe Commerce/Magento, CVSS 10.0), CVE-2026-81963 and CVE-2026-85880 (Microsoft Windows local privilege escalation, CVSS 7.8 each), and CVE-2026-86218 (N-able N-central pre-auth RCE, CVSS 10.0) to its Known Exploited Vulnerabilities catalog. Sansec researchers report the StyleSmuggler Magento flaw, actively exploited since September 4, lets unauthenticated attackers run code on vulnerable online stores and deploy web shells and backdoors; Microsoft confirmed active exploitation of both Windows flaws, and N-able shipped an emergency hotfix. Federal civilian agencies must patch the Windows flaws by September 22, 2026, and the remaining entries by September 11, 2026 under BOD 22-01.