Defensive self-check · CISA KEV 2026-09-08
Adobe Commerce and Magento CVE-2026-75650 self-check
CISA added CVE-2026-75650 on 2026-09-08. It concerns template handling in Adobe Commerce and Magento. Review the store you operate. This page does not include exploit steps.
Check these three things
- Version. Compare the Commerce or Magento version with the fixed release in the Adobe advisory.
- Templates. Review CMS pages and email templates changed since 2026-09-08 for content your staff did not edit.
- Admin users. Compare System → Permissions → All Users with the people who should have access.
What to do
Install the Adobe update first. After the update, remove template changes you cannot attribute to a staff edit and reset passwords for unexpected administrator accounts.
Vendor record: CISA KEV catalog, entry CVE-2026-75650.