“Adobe Commerce” — 27 distilled results

CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither fl

CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither flaw is known to be used in ransomware campaigns.

Adobe patches critical Magento zero-day exploited in attacks

A maximum-severity zero-day vulnerability called StyleSmuggler affecting Magento and Adobe Commerce was actively exploited starting September 4, 2026, to deploy Linux backdoors. Adobe released emergency patches (CVE-2026-75650) on September 8 after a three-day window of exposure.

Adobe Commerce faces a CRITICAL (CVSS 10) template engine flaw (CVE-2026-75650) allowing arbitrary code execution with no user interaction required. Update and monitor for patches. https:// radar.offs

Adobe Commerce faces a CRITICAL (CVSS 10) template engine flaw (CVE-2026-75650) allowing arbitrary code execution with no user interaction required. Update and monitor for patches.

CVE-2026-71362: Adobe Commerce and Magento — Adobe Commerce and Magento Incorrect Authorization Vulnerability

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes).

json:cisa-kev 5d ago