Alert

Alert 2026-98 Critical Zero-Day in Adobe Commerce and Magento Open Source

Affected product(s):

ProductAffected versionsFix
Adobe Commerce2.4.4‑2026‑aug, 2.4.5‑2026‑aug, 2.4.6‑2026‑aug, 2.4.7‑2026‑aug, 2.4.8‑2026‑aug, 2.4.9‑2026‑aug and earlierApply VULN‑39341 hotfix corresponding to the installed version
Adobe Commerce B2B1.3.3‑2026‑aug, 1.3.4‑2026‑aug, 1.4.2‑2026‑aug, 1.5.2‑2026‑aug, 1.5.3‑2026‑aug and earlierApply VULN‑39341 hotfix corresponding to the installed version
Magento Open Source2.4.6‑2026‑aug, 2.4.7‑2026‑aug, 2.4.8‑2026‑aug, 2.4.9‑2026‑aug and earlierApply VULN‑39341 hotfix corresponding to the installed version

Adobe officially tested the hotfix on the listed 2026-aug versions. Earlier versions within the affected branches are also vulnerable, but Adobe warns that the patch has not been officially validated on all of those legacy releases; in those cases, it is recommended to first upgrade to a supported version and apply the corresponding hotfix.

Description

Adobe released an emergency update to fix CVE‑2026‑75650, a vulnerability of critical severity with a CVSS 10.0 score that allows a remote unauthenticated attacker to execute arbitrary code on vulnerable Adobe Commerce and Magento Open Source installations.

The CVE‑2026‑75650 vulnerability affects the template rendering system of Magento/Adobe Commerce and allows a Server-Side Template Injection (SSTI) chain that can result in remote code execution without requiring authentication. The vulnerability is an improper neutralization of special elements used in a template engine, classified as CWE‑1336

Sansec’s research indicates that the attacker abuses a property called styles within the template mechanism. Through a specially crafted input, they can induce the dependency injection system and template processing to instantiate unexpected classes and execute PHP code on the server.

The observed malicious flow uses the creation of an email titled “Payment Transaction Failed Reminder” as a vehicle to trigger PHP code injection and cause execution on the server. The unauthenticated access and the ability to execute code make the impact maximum: an attacker can install persistence mechanisms, webshells, malware, steal configuration secrets, access databases, and modify e-commerce logic or payment processes.

Solution

The official solution consists of applying the Adobe hotfix VULN‑39341, published in bulletin APSB26‑146, for the specific version of Adobe Commerce, Adobe Commerce B2B, or Magento Open Source deployed. The hotfix fixes the unsafe handling of template values before unintended classes can be instantiated by the rendering engine.

https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/announcements/commerce-apsb26-146

Additional information: