Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Adobe disclosed active exploitation of a critical vulnerability in Adobe Commerce and Magento Open Source on September 7, 2026. Adobe’s response is a dedicated hotfix for CVE-2026-75650. A separate security bulletin published September 8 supplies September security-update builds—and explicitly says to install the hotfix in addition to those updates. Operators should check their product, branch, and B2B installation before choosing packages.

What happened, and which fix is urgent?

Adobe’s September 7, 2026 security bulletin APSB26-146 identifies CVE-2026-75650 as a critical flaw involving improper neutralization of special elements used in a template engine (CWE-1336). Adobe lists arbitrary code execution as the impact, says authentication is not required, and assigns the issue a CVSS 3.1 base score of 10.0. Most urgently, Adobe states: “Adobe is aware of CVE-2026-75650 being exploited in the wild.”

Adobe’s listed solution for that vulnerability is a dedicated hotfix for Adobe Commerce and Magento Open Source. The bulletin covers Adobe Commerce, Adobe Commerce B2B, and Magento Open Source versions through their respective 2026-Aug builds and earlier. The precise applicable package depends on the product and branch; consult APSB26-146 and the relevant release notes rather than assuming one hotfix package fits every installation.

How do the two September notices differ?

Notice Published What it addresses Adobe’s stated remediation
APSB26-146 September 7, 2026 CVE-2026-75650; Adobe reports in-the-wild exploitation. A specific hotfix for Adobe Commerce and Magento Open Source.
APSB26-138 September 8, 2026 September security updates addressing critical, important, and moderate vulnerabilities. Product-specific September 2026 security-update builds. Adobe says to apply the CVE-2026-75650 hotfix in addition to these updates.

Do not treat APSB26-138 as a substitute for the emergency hotfix. Adobe’s note in APSB26-138 explicitly requires the hotfix as an additional step. Adobe also says it is not aware of in-the-wild exploits for the issues addressed in APSB26-138; that statement applies to that bulletin’s issues, not to CVE-2026-75650.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which September security-update build matches the product?

APSB26-138 lists the following updated versions. Match the installed product family and branch to Adobe’s advisory and release notes before deployment.

Product September 2026 builds listed by Adobe
Adobe Commerce 2.4.9-2026-sep; 2.4.8-2026-sep; 2.4.7-2026-sep; 2.4.6-2026-sep; 2.4.5-2026-sep; 2.4.4-2026-sep
Adobe Commerce B2B 1.5.3-2026-sep; 1.5.2-2026-sep; 1.4.2-2026-sep; 1.3.4-2026-sep; 1.3.3-2026-sep
Magento Open Source 2.4.9-2026-sep; 2.4.8-2026-sep; 2.4.7-2026-sep

Commerce B2B has its own listed builds and a B2B-specific authorization issue appears in the September bulletin. If the B2B module is in use, verify its update requirements as well as those for the core Commerce platform.

What should store operators do?

  1. Identify the installation. Record whether it is Adobe Commerce, Adobe Commerce B2B, or Magento Open Source, along with the installed branch and current build.
  2. Read APSB26-146 for the matching hotfix. Verify the exact affected branch and hotfix instructions in Adobe’s advisory and its corresponding release notes; do not infer a package or installation command from the bulletin title alone.
  3. Apply the CVE-2026-75650 hotfix. Adobe reports active exploitation and lists this hotfix as the solution for the vulnerability.
  4. Apply the matching APSB26-138 security update as a separate action. Use the build for the installed product and branch, including the B2B build where applicable. Adobe says this update does not replace the hotfix.
  5. Validate the deployed versions and service. Confirm that the intended hotfix and security build are in place using your deployment records and Adobe’s instructions, then check that the storefront and relevant administrative functions operate as expected.

The bulletins establish the required fixes but do not, by themselves, provide a universal command sequence that applies to every deployment. Follow the instructions for the specific product, branch, and installation method.

What else does APSB26-138 address?

Among the September bulletin’s listed issues are CVE-2026-76200 and CVE-2026-76201, both critical stored cross-site scripting vulnerabilities with privilege-escalation impact. Adobe assigns each a CVSS base score of 9.3. The bulletin also lists incorrect-authorization and path-traversal issues. These are part of the monthly security-update scope; they are distinct from the separately disclosed, actively exploited CVE-2026-75650.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Adobe notes that, effective August 11, 2026, it may use a single CVE identifier for internally discovered vulnerabilities that share a severity rating and CWE category when a release contains systemic fixes. A CVE count alone therefore may not describe every underlying fix one-for-one.

How does this compare with earlier 2026 updates?

Adobe’s August 11, 2026 bulletin APSB26-92 listed August builds for Commerce, Commerce B2B, and Magento Open Source and said Adobe was not aware of in-the-wild exploitation for the issues covered there. That disclosure is limited to APSB26-92; it does not change the September 7 statement about CVE-2026-75650.

Adobe’s April 14, 2026 bulletin APSB26-42 covered stored cross-site scripting CVE-2026-27291, listing arbitrary code execution as the impact and a CVSS score of 8.7. That earlier advisory does not establish whether a particular installation has since been patched; check the current version and applicable release notes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the severity scores do—and do not—mean

The CVSS figures are vulnerability severity scores, not counts of affected stores, confirmed compromises, or estimates of financial loss. Adobe’s reviewed notices do not provide an incident count or affected-customer statistic. Adobe’s bulletin index lists APSB26-146 on September 7 and APSB26-138 on September 8, 2026; advisories and supported builds can change, so check the live Adobe notices and branch-specific release notes when planning deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.