Skip to main content
EVULNABLE
Home

CVE-2026-75650

Adobe — Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

CISA KEV · in the CISA KEV catalog since 2026-09-08

ExigentCISA deadline in 3 daysCISA KEVActively Exploited

What EVULNABLE says

Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Out-of-Band / Urgent Remediation

The priority band answers “how soon”, not “how bad” — see Methodology for what it weighs and where it abstains.

The evidence behind it

MeasureValueSource
CVSS base score 10.0 NVD
FIRST EPSS 0.007 (50th pctl) FIRST
Actively exploited Confirmed CISA KEV
Ransomware campaign use Unknown or none CISA KEV
CISA remediation deadline 2026-09-11 — CISA deadline in 3 days CISA KEV

The primary records

This page is an opinion about urgency. Where it and a source of record disagree, the source of record is the record.

Where this sits

CVE-2026-75650 is one of the entries ranked on the priority feed and in the non-Microsoft advisories.