---
id: CVE-2026-75650
title: >-
  Adobe Commerce is affected by an Improper Neutralization of Special Elements
  Used in a Template Engine vulnerability that could result in arbitrary code
  execution in the context of the current user
summary: >-
  Adobe Commerce is affected by an Improper Neutralization of Special Elements
  Used in a Template Engine vulnerability that could result in arbitrary code
  execution in the context of the current user. An attacker could exploit this
  vulnera…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-1336
vendor: adobe
product: commerce
affected:
  - commerce < 2.4.4
  - commerce = 2.4.4
  - commerce = 2.4.5
  - commerce = 2.4.6
  - commerce = 2.4.7
  - commerce = 2.4.8
  - commerce = 2.4.9
  - commerce_b2b < 1.3.3
  - commerce_b2b = 1.3.3
  - commerce_b2b = 1.3.4
  - commerce_b2b = 1.4.2
  - commerce_b2b = 1.5.2
  - commerce_b2b = 1.5.3
  - magento < 2.4.6
  - magento = 2.4.6
  - magento = 2.4.7
  - magento = 2.4.8
  - magento = 2.4.9
patched:
  - commerce 2.4.4
  - commerce_b2b 1.3.3
  - magento 2.4.6
published: '2026-09-07'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T05:18:07.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75650'
references:
  - url: 'https://helpx.adobe.com/security/products/magento/apsb26-146.html'
    label: psirt@adobe.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-08T18:44:04.878935Z'
epss: 0.02148
epssPercentile: 0.81057
kev: true
kevDateAdded: '2026-09-08'
kevDueDate: '2026-09-11'
kevRansomware: false
exploits:
  github: 5
  githubRepos:
    - 'https://github.com/fortbridge/stylesmuggler'
    - 'https://github.com/dinosn/cve-2026-75650-magento-validation-lab'
    - 'https://github.com/disrex-group/stylesmuggler-adobe-patches'
  checkedAt: '2026-09-21T15:30:37.405Z'
zeroDay: true
ingestedAt: '2026-09-08T15:33:26.980Z'
---

## Overview

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

## Affected

- `commerce < 2.4.4`
- `commerce = 2.4.4`
- `commerce = 2.4.5`
- `commerce = 2.4.6`
- `commerce = 2.4.7`
- `commerce = 2.4.8`
- `commerce = 2.4.9`
- `commerce_b2b < 1.3.3`
- `commerce_b2b = 1.3.3`
- `commerce_b2b = 1.3.4`
- `commerce_b2b = 1.4.2`
- `commerce_b2b = 1.5.2`
- `commerce_b2b = 1.5.3`
- `magento < 2.4.6`
- `magento = 2.4.6`
- `magento = 2.4.7`
- `magento = 2.4.8`
- `magento = 2.4.9`

## Remediation

Upgrade past the affected range:

- `commerce 2.4.4`
- `commerce_b2b 1.3.3`
- `magento 2.4.6`
