CVE-2026-75650 deserves urgent attention because Adobe says attackers are exploiting it in the wild. It is a critical, unauthenticated remote-code-execution flaw in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Adobe assigns it a CVSS 3.1 score of 10.0 and Priority 1 hotfix guidance. The key operational detail: the CVE-specific hotfix is separate from Adobe’s broader September security update, and Adobe says to install both where applicable.
What CVE-2026-75650 is—and why it is urgent
Adobe classifies CVE-2026-75650 as improper neutralization of special elements used in a template engine (CWE-1336), with arbitrary code execution as the impact. Its bulletin describes a network attack requiring low complexity, no privileges, and no user interaction. In practical terms, an attacker does not need an account or a victim to click something to attempt exploitation against a vulnerable server.
Adobe’s September 7, 2026 bulletin states: “Adobe is aware of CVE-2026-75650 being exploited in the wild.” The confirmed exploitation, combined with the lack of authentication requirements and the potential for arbitrary code execution, is why affected operators should prioritize remediation rather than treating this as a routine patch.
Adobe assigns the flaw a CVSS 3.1 base score of 10.0 and Priority 1 status. The score summarizes the vulnerability’s severity; it does not establish how many systems are exposed or compromised. The vendor advisories do not quantify either population.
#1 Best Overall
- USB Fingerprint Key Reader suitable for Windows10/11 Hello features.
- 360 Degrees Detection:Fingerprints can be read from any angle in 360Degrees, set up to 10 Fingerprint IDs.
- 0.05 seconds:Fingerprints authenticated within 0.05seconds. Logins faster and more secure.
- With intelligent learning algorithm, detection and authentication is faster and more secure.
- Advanced Protections:Safely protect your logins and data with Fingerprint Security Device.
Which Adobe Commerce and Magento versions are affected?
Adobe’s APSB26-146 bulletin lists the following affected product ranges. Check the vendor bulletin for the precise release status and corresponding solution for your installation.
| Product | Affected versions listed by Adobe |
|---|---|
| Adobe Commerce | 2.4.4 through 2.4.9-2026-aug and earlier |
| Adobe Commerce B2B | 1.3.3 through 1.5.3-2026-aug and earlier |
| Magento Open Source | 2.4.6 through 2.4.9-2026-aug and earlier |
These are vendor-listed release ranges, not a claim that every installation in them is reachable from the internet or has been attacked. Confirm your exact product and installed version against Adobe’s APSB26-146 security bulletin.
Rank #2
- Protect Online Account - Offer a strong factor authentication to your online account. Never lose your accounts through password theft, phishing, hacking or keylogging scams.
- Universal Compatibility - The Thetis U2F key can be used on any websites which support U2F protocol with the latest Chrome installed on your Windows, Mac OS or Linux. (Important Note: Not compatible with any email clients including Apple Mail, Mozilla Thunderbird or Microsoft Outlook)
- FIDO-U2f-Certified - Safety is our priority. Certified by world's largest Ecosystem for Standards-based, interoperable Authentication. Only support U2F protocol (No UAF or OTP). Provide low-cost and simple solution with high security.
- Extremly Durable - Designed with a 360° rotating metal cover that shields the USB connector when not in use. Also, crafted from a durable aluminum alloy to protect the Key from drops, bumps and scratches.
- Portable Design - Compact, ultra-portable design allows you to take your FIDO key anywhere you need it.
What to install: the CVE hotfix and the separate security update
Adobe published APSB26-146 on September 7, 2026, specifically addressing CVE-2026-75650. The bulletin identifies a Priority 1 hotfix for Adobe Commerce and Magento Open Source. The next day, Adobe published APSB26-138 for additional security issues. That bulletin explicitly says the CVE-2026-75650 hotfix should be applied in addition to the updates in APSB26-138.
- Identify the installation. Record whether it is Adobe Commerce, Adobe Commerce B2B, or Magento Open Source, and confirm the installed version.
- Compare it with Adobe’s affected-version and solution tables. Use APSB26-146 for the CVE-specific hotfix and APSB26-138 for the separate security update.
- Apply the CVE-specific hotfix using Adobe’s deployment instructions. Do not assume the broader APSB26-138 update includes or replaces it.
- Apply the APSB26-138 update when it is applicable to your product and version. Adobe’s bulletin says to use it in addition to the hotfix.
- Verify the running installation against Adobe’s release guidance. Deployment details can vary by product and version, so follow the vendor’s linked instructions rather than relying on a generic command or procedure.
APSB26-138 lists September 2026 releases for Adobe Commerce and Commerce B2B and Magento Open Source versions 2.4.7 through 2.4.9-2026-sep in its visible solution table. Use Adobe’s tables to determine the applicable release for your specific product; the general update is not a substitute for the separate CVE hotfix.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Why the two Adobe bulletins do not contradict each other
APSB26-146 concerns CVE-2026-75650 and says Adobe knows it is being exploited in the wild. APSB26-138 covers a different set of vulnerabilities and says Adobe was not aware of exploits for the issues addressed in that bulletin. It then points readers back to the September 7 hotfix and says to apply it in addition. The differing exploitation statements refer to different issue sets; APSB26-138 does not withdraw Adobe’s warning about CVE-2026-75650.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the severity means for operators
The risk comes from the combination of network reachability, low attack complexity, no required privileges, no user interaction, and the potential for arbitrary code execution. Confirmed in-the-wild exploitation makes timely patching especially important for affected deployments that an attacker can reach.
Rank #4
- Point 1 【WINDOWS HELLO COMPATIBLE】 Works with Windows 10 and Windows 11 Windows Hello as a Windows Hello fingerprint reader. This fingerprint reader for Windows 11 supports one-touch fingerprint login to replace passwords, for quick unlock of laptops and desktops.
- Point 2 【PLUG & PLAY, NO DRIVERS REQUIRED】 This plug and play USB fingerprint reader works as a usb fingerprint reader windows 11 dongle. Insert it into any USB port for recognition without extra software or drivers. Its slim compact shape will not block adjacent USB slots on your PC, suitable as a fingerprint reader for pc.
- Point 3 【360° FAST FINGERPRINT SCANNING】 This fingerprint scanner features a 360° all-angle sensor for steady fingerprint matching. The biometric sensor can store multiple fingerprints at the same time, matching the use of multi-user shared desktop and laptop computers.
- Point 4 【ENCRYPTED BIOMETRIC SECURITY】 This fingerprint reader has a built-in encryption chip. The chip blocks unauthorized access to PC login accounts, personal files and stored data. It adds password-free security for fingerprint login on Windows devices.
- Point 5 【PORTABLE FOR WINDOWS DEVICES】 This lightweight biometric finger print device fits home, office and travel scenarios. It works with most Windows laptops, desktops and all-in-one PCs, for convenient unlock when you carry computers outside.
- The advisories establish affected release ranges and exploitation status, but not how many installations are exposed.
- They do not establish that every affected host has been compromised.
- Installing the hotfix addresses the vulnerability; it does not by itself determine whether an installation was compromised before remediation.
CERT-In’s CIVN-2026-0458, dated September 16, 2026, also characterizes the issue as a critical remote-code-execution vulnerability exploitable by an unauthenticated remote attacker. Its notice is available at CERT-In Vulnerability Note CIVN-2026-0458.
Quick Recap
Best Value
- Support Windows 10 / 11 Hello Biometric Authentication: Plug and play with updated Windows OS, provides instant access for Windows computers. Tasks such as login, sign in or unlock can be accomplished with a touch of a finger, no need to remember usernames and passwords
- Up to 5 Fingerprint Registration: Allow family members, close friends, or colleagues to gain access to a single computer. 360° all direction fingerprint registering for better accuracy and faster response.
- Paralleled Software Support: With Smart ID Encryption, encrypting your files has never been so easy. You can specify a folder as an encrypted zone, once a file is copied into the folder, it automatically be encrypted.
- Gets Smarter Over Time: With each fingerprint registry, the scanned data is added to the profile of the enrolled finger. So, the more you use it, the more accurate it gets. Allowing faster access.
- All You Need in a Nano Formfactor: Small and lightweight, takes up no space. Drop it in your pocket and you wouldn't even notice a thing.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

