← Back to feed
Vulnerabilities & PatchesEmerging2 sourcesSep 8, 2026 · 00:00via CISA KEV

CVE-2026-75650 - Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

Brief

Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

Read more on CISA KEV

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

CISA KEVPrimary··trust 1.52

CVE-2026-75650 - Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

Read more →
CVEFeed··trust 1.18

CVE-2026-75650 - Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

CVE ID : CVE-2026-75650

Published : Sept. 7, 2026, 8:17 p. m.

  • 32 minutes ago

Description : Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Severity: 10.0

  • CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more →