Skip to content
skopnix
actively exploited · CISA KEV

CVE-2026-75650

NVD CRITICAL 10 · published 2026-09-07 · 1 on the wire

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Exploited in the wild

Yes

CISA added it 2026-09-08. An observation, not a forecast.

EPSS · 30-day forecast

2%

Chance of exploitation in the next 30 days, 81th percentile of all CVEs. A forecast; KEV outranks it.

CVSS · NVD

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Internet exposure

No exposure census on this CVE's dispatches.

On the wire1
References
Early access

Watch this one?

Early access opens alerts first — one email when a CVE you follow lands on KEV or an adversary you follow lands on the wire. Nothing else, ever.

bot-protected