CRITICAL

CVE-2026-75650

Adobe Commerce 2026-09-07 CVSS v3.1
CVSS
10
KEV

Description

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Weakness (CWE)

CWE-1336

EPSS Score

2.15%
Probability of exploitation in next 30 days
81.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE