CVE-2026-75650: Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Published Sep 7, 2026
·Updated
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
1 affected component
Adobe Commerce
Event History
Sep 7, 2026
CVE Published
via MITRE·08:17 PM
Data Sourced
via MITRE·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Can this be exploited remotely without an account or user interaction?
Yes. The supplied vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction.
2
What level of access could successful exploitation provide?
Successful exploitation could allow arbitrary code execution in the context of the current user. The impact is rated high for confidentiality, integrity, and availability, with changed scope.