CVE-2026-75650
Received Received - Intake

Improper Template Neutralization in Adobe Commerce

Vulnerability report for CVE-2026-75650, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: Adobe Systems Incorporated

Description

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
adobe commerce *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1336 The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Adobe Commerce has an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. This flaw allows an attacker to execute arbitrary code on the affected system with the privileges of the current user. The vulnerability does not require any user interaction to be exploited.

Impact Analysis

This vulnerability could allow an attacker to take full control of your Adobe Commerce system, steal sensitive data, install malware, or disrupt operations. Since exploitation does not require user interaction, attackers can remotely compromise systems easily.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements. Non-compliance may result in legal penalties, fines, or reputational damage due to data breaches.

Mitigation Strategies

Apply the latest security patches or updates provided by Adobe Commerce immediately to address the Improper Neutralization of Special Elements Used in a Template Engine vulnerability. Since exploitation does not require user interaction and has a CVSS score of 10.0, prioritize patching without delay.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75650. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart