This briefing was produced by AI from the linked sources and is scheduled for human editorial review within 24 hours. Read the sources directly for material decisions.
EVIDENCE — Adobe published APSB26-146 on 7 September 2026 for CVE-2026-75650, an improper neutralization flaw in the Commerce template engine. Adobe assigns it CVSS 10.0 and says an unauthenticated network attacker can execute arbitrary code. The affected scope includes Adobe Commerce 2.4.4 through the August 2026 builds of 2.4.9, associated Commerce B2B releases, and Magento Open Source 2.4.6 through the August 2026 builds of 2.4.9. Adobe says exploitation is occurring in the wild against Commerce merchants.
THE FIX IS A PATCH, NOT A VERSION NUMBER — Adobe directs affected Commerce and Magento installations to apply the version-appropriate VULN-39341 hotfix. The company notes that the hotfix was tested only against its listed August 2026 builds and may work on other supported releases without having been officially verified. For Adobe Commerce on Cloud, Adobe also warns that patch state is not easy to determine from the outside and provides a Quality Patches Tool command that should report VULN-39341 as Applied. A successful deployment job is therefore not the same evidence as a verified runtime patch state.
CODE EXECUTION TURNS SECRET STORAGE INTO INCIDENT SCOPE — Adobe says full remediation requires rotating the Commerce encryption key and every credential that may have been encrypted or exposed through it. That list includes administrator passwords, REST, SOAP, and GraphQL integration tokens, OAuth client secrets, payment-gateway credentials, database credentials, SSH and deployment keys, privileged cron or service-account credentials, and keys used by shipping, tax, and other extensions. Rotating the encryption key alone does not invalidate a credential already copied by an attacker; each credential must be rotated at its authoritative provider.
THE RESPONSE CLOCK IS THREE DAYS — On 8 September, CISA added CVE-2026-75650 to the Known Exploited Vulnerabilities catalog, set 11 September 2026 as the remediation due date, and marked forensic triage as required under its current federal guidance. CISA records ransomware use as unknown. Those fields establish exploitation and urgency, not the identity of the attacker, campaign scale, or whether every exposed merchant was compromised.
WHAT TO CHECK — Inventory Adobe Commerce, Commerce B2B, and Magento Open Source deployments by exact release and hosting model. Apply VULN-39341 using Adobe's version-specific package, verify that the patch reports Applied, then rotate the encryption key and all associated credentials at their source. Preserve evidence before destructive cleanup; review unexpected administrator and integration changes, newly issued tokens, unfamiliar code or file changes, deployment-key use, scheduled tasks, and anomalous outbound or payment-service activity. Treat extensions and downstream services as part of the same investigation boundary, and use Adobe support or an authorized incident-response team when patch compatibility or compromise status is uncertain.