Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If your Adobe Commerce, Adobe Commerce B2B, or Magento Open Source store has a /graphql endpoint reachable from the internet and runs an affected release, treat CVE-2026-75650 as an urgent patching task. Adobe classifies it as a critical template-engine flaw that can allow arbitrary code execution without authentication, and Adobe states that it is being exploited in the wild. The /graphql exposure is the condition that opens this attack path. The Adobe version table and the hotfix decide whether a particular store is vulnerable and whether it has been remediated.

Why /graphql exposure is the condition that matters

The Australian Cyber Security Centre (ACSC), in its alert on active exploitation of Adobe Commerce and Magento Open Source, states: “Exploitation requires the /graphql endpoint to be exposed.” That sentence defines the reachability side of the risk. Exposure means an untrusted party can send requests to the endpoint, which in practice means the public internet. It does not mean GraphQL is inherently insecure, and it does not mean every internet-facing GraphQL service is affected. The flaw sits in how Magento processes templates. /graphql is the route the attack uses to reach that code path.

Check reachability from outside your network

Run the following from a machine outside your office or hosting network, and repeat it from a second network if you have one:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -I https://your-store.example/graphql

Any HTTP response, including an error status, means the request got past the network edge, which is the exposure condition the ACSC describes. A timeout or refusal from one location does not prove the endpoint is closed everywhere, because load balancers, CDNs, and firewall rules can treat different hostnames and paths differently.

Exposure and vulnerability are separate questions

Two checks answer two different questions, and a store needs both answers:

  • Exposure: Can an untrusted party reach /graphql? This is the precondition the ACSC names.
  • Software state: Does the installed release fall inside Adobe’s affected range, and does it include the CVE-2026-75650 hotfix? Adobe’s bulletin answers this, not the URL.

A reachable endpoint on a release that already includes the fix is a lower priority than a reachable endpoint on an affected, unpatched release. An endpoint that is unreachable today on an affected release is still an affected release, because a later configuration change, a new load balancer rule, or a CDN change can expose it again.

Rank #2
Sale
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  • Comes with secure packaging
  • It can be a gift item
  • Easy to read text

Severity, exploitation, and timeline

Adobe’s security bulletin APSB26-146 classifies CVE-2026-75650 as Critical. It describes the issue as improper neutralization of special elements used in a template engine, lists arbitrary code execution as the impact, and states that authentication is not required. The CVSS 3.1 base score is 10.0, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. In plain terms, the flaw is reachable over the network, needs no privileges and no user interaction, can affect resources beyond the vulnerable component, and carries high impact to confidentiality, integrity, and availability. Adobe also states: “Adobe is aware of CVE-2026-75650 being exploited in the wild.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Date (2026) Source What it establishes
September 7 Adobe, bulletin APSB26-146 published Severity, affected releases, exploitation statement, and a hotfix
September 8 CERT Vanuatu, Advisory 273 Secondary technical account of a GraphQL-related template attack chain
September 9 Adobe, bulletin APSB26-146 updated Revision of the bulletin; the change itself is not stated
September 14 Akamai Security Intelligence Group analysis Technical walkthrough; reports active exploitation attempts and a CVSS 10.0 rating

No verified count of compromised or affected stores appears in the vendor, government, or Akamai material, so none is offered here. Your own inventory is the only reliable measure of your exposure.

Affected releases and the fix

Adobe’s bulletin APSB26-146 lists the following releases as affected. Use this table as the authoritative list and match your installed release identifier against it.

Product Affected releases (per Adobe APSB26-146)
Adobe Commerce 2.4.4-2026-aug and earlier through 2.4.9-2026-aug and earlier
Adobe Commerce B2B 1.3.3-2026-aug and earlier; 1.3.4-2026-aug and earlier; 1.4.2-2026-aug and earlier; 1.5.2-2026-aug and earlier; 1.5.3-2026-aug and earlier
Magento Open Source 2.4.6-2026-aug and earlier through 2.4.9-2026-aug and earlier

Releases outside these ranges are not listed as affected. If you run an older line, confirm with Adobe’s bulletin before assuming it is out of scope.

Adobe’s solution entry lists a hotfix for CVE-2026-75650 for Adobe Commerce and Magento Open Source, available for all platforms, and points to the hotfix release notes. Adobe also recommends updating to the newest version. The solution entry names those two products, so check the bulletin for B2B-specific guidance rather than assuming the same hotfix applies to Adobe Commerce B2B installations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the attack chain works

Akamai’s analysis describes malicious PHP delivered through HTTP headers and parameters on GraphQL requests. That code is introduced into Magento’s template-processing path and later executed during automated email rendering. CERT Vanuatu’s Advisory 273, dated September 8, 2026, describes a similar chain involving GraphQL styles handling and a payment transaction reminder template. The two accounts describe the same general pattern with different details. Use them to understand the mechanism, and use Adobe’s bulletin for authoritative version and remediation statements.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Response order

  1. Inventory every installation. List production, staging, and any B2B-enabled instances. On each one, run bin/magento --version from the Magento root directory and record the output. If the output does not map cleanly onto the table’s identifiers, check the installed release notes rather than guessing.
  2. Confirm exposure. Run the reachability check above from outside your network for every host and domain that serves the store.
  3. Apply the hotfix or move to a fixed release. Follow Adobe’s hotfix release notes exactly. Akamai calls prompt application of the vendor patch the most effective defense. After installation, confirm the installed state the release notes describe before recording the instance as remediated.
  4. Restrict and monitor if patching must wait. The ACSC advises restricting and monitoring access when no patch is available for a version. The options and their limits are covered in the comparison below.
  5. Review telemetry. Look for unusual system activity, unexpected scheduled tasks, suspicious log entries, unusual template processing, and failed notifications, all of which the ACSC calls out. Failed or malformed transactional emails deserve particular attention, because the attack chain runs during automated email rendering.
  6. Escalate if you find indicators. Treat any sign of compromise as an incident and move to forensic investigation. Applying the patch alone does not establish that an existing compromise has been removed.
  7. Coordinate with your provider. If a managed service provider or enterprise IT team operates the store, ask it to confirm patch status and monitoring for each instance, as the ACSC advises.

Interim controls compared

These controls supplement the patch. None of them replaces it.

Control What it does Limitation
Adobe hotfix or a release containing the fix Remediates CVE-2026-75650 directly Must be installed according to Adobe’s notes and verified afterward
Endpoint restriction Reduces which networks can reach /graphql Check which storefront or integration features depend on GraphQL first; blanket blocking can break functionality
Monitoring Helps detect exploitation attempts and signs of post-exploitation activity Detects activity; it does not block requests or fix the flaw
Web application firewall Akamai reports that, for its App & API Protector Adaptive Security Engine, existing CMD Injection protections blocked the primary GraphQL header- and parameter-based vectors it analyzed, and that it continued validating coverage across other vectors These are product-specific observations reported by the vendor. They are not a guarantee for other WAFs or for every exploit variant, and they do not replace the patch

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.