Adobe disclosed active exploitation of a critical vulnerability in Adobe Commerce and Magento Open Source on September 7, 2026. Adobe’s response is a dedicated hotfix for CVE-2026-75650. A separate security bulletin published September 8 supplies September security-update builds—and explicitly says to install the hotfix in addition to those updates. Operators should check their product, branch, and B2B installation before choosing packages.
What happened, and which fix is urgent?
Adobe’s September 7, 2026 security bulletin APSB26-146 identifies CVE-2026-75650 as a critical flaw involving improper neutralization of special elements used in a template engine (CWE-1336). Adobe lists arbitrary code execution as the impact, says authentication is not required, and assigns the issue a CVSS 3.1 base score of 10.0. Most urgently, Adobe states: “Adobe is aware of CVE-2026-75650 being exploited in the wild.”
Adobe’s listed solution for that vulnerability is a dedicated hotfix for Adobe Commerce and Magento Open Source. The bulletin covers Adobe Commerce, Adobe Commerce B2B, and Magento Open Source versions through their respective 2026-Aug builds and earlier. The precise applicable package depends on the product and branch; consult APSB26-146 and the relevant release notes rather than assuming one hotfix package fits every installation.
How do the two September notices differ?
| Notice | Published | What it addresses | Adobe’s stated remediation |
|---|---|---|---|
| APSB26-146 | September 7, 2026 | CVE-2026-75650; Adobe reports in-the-wild exploitation. | A specific hotfix for Adobe Commerce and Magento Open Source. |
| APSB26-138 | September 8, 2026 | September security updates addressing critical, important, and moderate vulnerabilities. | Product-specific September 2026 security-update builds. Adobe says to apply the CVE-2026-75650 hotfix in addition to these updates. |
Do not treat APSB26-138 as a substitute for the emergency hotfix. Adobe’s note in APSB26-138 explicitly requires the hotfix as an additional step. Adobe also says it is not aware of in-the-wild exploits for the issues addressed in APSB26-138; that statement applies to that bulletin’s issues, not to CVE-2026-75650.
Recommended Free Tools
#1 Best Overall
Which September security-update build matches the product?
APSB26-138 lists the following updated versions. Match the installed product family and branch to Adobe’s advisory and release notes before deployment.
| Product | September 2026 builds listed by Adobe |
|---|---|
| Adobe Commerce | 2.4.9-2026-sep; 2.4.8-2026-sep; 2.4.7-2026-sep; 2.4.6-2026-sep; 2.4.5-2026-sep; 2.4.4-2026-sep |
| Adobe Commerce B2B | 1.5.3-2026-sep; 1.5.2-2026-sep; 1.4.2-2026-sep; 1.3.4-2026-sep; 1.3.3-2026-sep |
| Magento Open Source | 2.4.9-2026-sep; 2.4.8-2026-sep; 2.4.7-2026-sep |
Commerce B2B has its own listed builds and a B2B-specific authorization issue appears in the September bulletin. If the B2B module is in use, verify its update requirements as well as those for the core Commerce platform.
What should store operators do?
- Identify the installation. Record whether it is Adobe Commerce, Adobe Commerce B2B, or Magento Open Source, along with the installed branch and current build.
- Read APSB26-146 for the matching hotfix. Verify the exact affected branch and hotfix instructions in Adobe’s advisory and its corresponding release notes; do not infer a package or installation command from the bulletin title alone.
- Apply the CVE-2026-75650 hotfix. Adobe reports active exploitation and lists this hotfix as the solution for the vulnerability.
- Apply the matching APSB26-138 security update as a separate action. Use the build for the installed product and branch, including the B2B build where applicable. Adobe says this update does not replace the hotfix.
- Validate the deployed versions and service. Confirm that the intended hotfix and security build are in place using your deployment records and Adobe’s instructions, then check that the storefront and relevant administrative functions operate as expected.
The bulletins establish the required fixes but do not, by themselves, provide a universal command sequence that applies to every deployment. Follow the instructions for the specific product, branch, and installation method.
What else does APSB26-138 address?
Among the September bulletin’s listed issues are CVE-2026-76200 and CVE-2026-76201, both critical stored cross-site scripting vulnerabilities with privilege-escalation impact. Adobe assigns each a CVSS base score of 9.3. The bulletin also lists incorrect-authorization and path-traversal issues. These are part of the monthly security-update scope; they are distinct from the separately disclosed, actively exploited CVE-2026-75650.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRank #3
Adobe notes that, effective August 11, 2026, it may use a single CVE identifier for internally discovered vulnerabilities that share a severity rating and CWE category when a release contains systemic fixes. A CVE count alone therefore may not describe every underlying fix one-for-one.
How does this compare with earlier 2026 updates?
Adobe’s August 11, 2026 bulletin APSB26-92 listed August builds for Commerce, Commerce B2B, and Magento Open Source and said Adobe was not aware of in-the-wild exploitation for the issues covered there. That disclosure is limited to APSB26-92; it does not change the September 7 statement about CVE-2026-75650.
Rank #4
Adobe’s April 14, 2026 bulletin APSB26-42 covered stored cross-site scripting CVE-2026-27291, listing arbitrary code execution as the impact and a CVSS score of 8.7. That earlier advisory does not establish whether a particular installation has since been patched; check the current version and applicable release notes.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the severity scores do—and do not—mean
The CVSS figures are vulnerability severity scores, not counts of affected stores, confirmed compromises, or estimates of financial loss. Adobe’s reviewed notices do not provide an incident count or affected-customer statistic. Adobe’s bulletin index lists APSB26-146 on September 7 and APSB26-138 on September 8, 2026; advisories and supported builds can change, so check the live Adobe notices and branch-specific release notes when planning deployment.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

