WHAT HAPPENED
Adobe Commerce and Magento Open Source are actively exploiting this vulnerability. Attackers smuggle malicious PHP code into Magento’s template-processing chain via HTTP headers and parameters, later executing it during automated email rendering. We continue to validate detection coverage across all observed exploitation vectors for this vulnerability. Vulnerability details CVE-2026-75650 is a critical remote code execution vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. The flaw allows an unauthenticated attacker to inject PHP code into the platform’s template engine, and later execute it on the server.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY