An exploited flaw in commerce servers

Adobe published APSB26-146 on 7 September for CVE-2026-75650, an improper neutralisation flaw in a template engine. Adobe rates it critical and says an unauthenticated attacker could achieve arbitrary code execution on an affected installation. The company is aware of exploitation in the wild targeting Adobe Commerce merchants.

The affected range includes Adobe Commerce 2.4.4 through the August 2026 builds of 2.4.9, associated Adobe Commerce B2B releases, and Magento Open Source 2.4.6 through the August 2026 builds of 2.4.9. The exact affected versions and applicable patch vary, so operators should match their deployed release to Adobe's current table rather than reuse a package chosen for another branch.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 8 September and calls for vendor mitigations. Its deadline applies to US federal agencies, not UK businesses, but the catalogue entry independently confirms known exploitation and makes this a priority ahead of an ordinary patch cycle. Neither source identifies every victim or says that every vulnerable store has been compromised.

[1][2][3]

Installing the patch is only the first half

Adobe provides a version-specific hotfix rather than merely advising an upgrade. Its knowledge-base article says full remediation also requires rotation of the Commerce encryption key and all credentials that may have been encrypted or exposed through it. Rotating only the key does not invalidate a credential that an attacker may already possess.

That distinction matters because a commerce platform often connects to payment, fulfilment, tax, shipping, database and automation services. Adobe tells operators to rotate affected credentials at their source, including integration tokens, connected-application secrets, administrative passwords and privileged service credentials. The work therefore needs application owners and relevant suppliers, not just somebody able to copy a patch onto the server.

Treat a successful installation message as evidence of deployment, not proof that no compromise occurred. Adobe provides a status check for its cloud customers and CISA marks this catalogue entry as requiring forensic triage for US federal systems. UK organisations should preserve useful logs and involve their incident-response lead where local evidence, unexplained changes or credential use suggests compromise.

[2][3]

What operators should do

First, establish whether the organisation or a hosting supplier runs an affected Adobe Commerce, Adobe Commerce B2B or Magento Open Source version. Record the exact release, hosting model, responsible owner and relevant integrations. Ask managed providers for evidence tied to the named CVE rather than a general assurance that patching is automatic.

Apply the hotfix listed by Adobe for that exact version through the normal tested change process, following the vendor instructions and taking the service precautions those instructions require. Confirm that the patch is present after deployment. If an installation cannot be corrected promptly, escalate the exposure and agree proportionate containment with the service owner; do not assume a web application firewall replaces the vendor fix.

After patching, rotate the Commerce encryption key and the credentials within Adobe's stated scope. Coordinate changes so integrations do not silently fail, validate important customer journeys afterwards, and retain a record of what was rotated, where and by whom. Review application, administrative and infrastructure logs from the relevant period for unexpected access or changes, escalating credible indicators through the organisation's incident process.

  • Inventory affected versions and assign a named owner.
  • Apply Adobe's version-specific hotfix and verify its status.
  • Rotate the encryption key and potentially exposed credentials at source.
  • Check important integrations and customer journeys after the change.
  • Preserve and review relevant evidence where compromise is suspected.
[1][2][3]

The Beekeeper view

This is not a patch-and-close ticket. Adobe's own remediation joins a software fix to credential replacement because the vulnerable system may hold secrets that remain useful after its code is corrected. Completion should therefore mean the correct hotfix is verified, exposed credentials are invalidated at their source, integrations are working with replacements and any signs of misuse have an owner.

For businesses buying a managed commerce service, the useful question is specific: can the provider show that CVE-2026-75650 is patched on the deployed version and that the required credential work has been completed? A generic statement about being fully managed is not the same evidence.

[1][2][3]
Identify affected Adobe Commerce and Magento Open Source installations, apply Adobe's version-specific hotfix, verify it, then rotate the encryption key and every credential that may have been protected by it.

Primary sources

  1. Security update available for Adobe Commerce | APSB26-146 — Adobe, 7 September 2026
  2. Urgent Action Required: Critical Security Update Available for Adobe Commerce (APSB26-146) — Adobe Commerce, 8 September 2026
  3. Known Exploited Vulnerabilities Catalog: CVE-2026-75650 — Cybersecurity and Infrastructure Security Agency, 8 September 2026

Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.