Magento Security Alert: What Store Owners Need to Know About the September 2026 Vulnerability

E-commerce6 min read

Adobe has warned about a critical, actively exploited Magento and Adobe Commerce vulnerability. Here is what store owners should check, patch and secure now.


If your business runs Magento Open Source or Adobe Commerce, there is a security update you should not ignore.

On September 7, 2026, Adobe published security bulletin APSB26-146 for a critical vulnerability, CVE-2026-75650. Adobe says the vulnerability can allow arbitrary code execution, does not require authentication to exploit, and is being exploited in the wild. Adobe rates it CVSS 10.0 / Critical.

A separate Adobe security update, APSB26-138, was published on September 8. Adobe specifically says merchants should apply the CVE-2026-75650 hotfix in addition to the September security updates.

Adobe Security Bulletin APSB26-146

Adobe September 2026 Security Update APSB26-138

Why This Magento Security Issue Matters

The most important detail is not the CVE number.

It is the combination of:

  • Critical severity
  • CVSS score of 10.0
  • No authentication required
  • Potential arbitrary code execution
  • Known exploitation in the wild

In simple terms, a vulnerable store may give an attacker a path to execute code on the affected installation without first having a legitimate account.

For an ecommerce business, that can affect customer data, admin access, integrations, credentials, website content and business operations.

Adobe's warning about active exploitation is enough reason to treat the issue as urgent.

What Is CVE-2026-75650?

Adobe classifies CVE-2026-75650 as an improper neutralization of special elements used in a template engine (CWE-1336).

The stated impact is:

Arbitrary code execution

Adobe also states that authentication is not required to exploit the vulnerability and assigns it a CVSS base score of 10.0.

You do not need to understand the internal template-engine mechanics to understand the business decision:

If your Magento installation is affected, this is a patching priority.

Which Magento Versions Are Affected?

Adobe's APSB26-146 bulletin lists affected August 2026 builds and earlier across multiple Adobe Commerce release lines.

Adobe Commerce

Affected lines include:

  • 2.4.9-2026-aug and earlier
  • 2.4.8-2026-aug and earlier
  • 2.4.7-2026-aug and earlier
  • 2.4.6-2026-aug and earlier
  • 2.4.5-2026-aug and earlier
  • 2.4.4-2026-aug and earlier

Magento Open Source

Affected lines listed by Adobe include:

  • 2.4.9-2026-aug and earlier
  • 2.4.8-2026-aug and earlier
  • 2.4.7-2026-aug and earlier
  • 2.4.6-2026-aug and earlier

Adobe also lists affected Adobe Commerce B2B releases.

Your major version alone is not enough to determine your exact remediation path. Magento patch levels matter.

For example:

2.4.7 and 2.4.7-p10 are not the same installation state.

Always check the exact version and patch level before deciding what to apply.

What Should Magento Store Owners Do Now?

1. Find your exact Magento version

Start by confirming what is actually running in production.

Check:

  • Magento / Adobe Commerce version
  • Patch level
  • B2B version, if applicable
  • Cloud or on-premises deployment
  • Custom modules
  • Recent security patches already applied

Do not rely on:

“Our developer said we're on 2.4.7.”

Get the exact installed version.

2. Apply the CVE-2026-75650 hotfix

Adobe provides version-specific remediation for the vulnerability.

Use the hotfix and instructions that match your exact Magento or Adobe Commerce version.

Read Adobe's hotfix instructions

Do not assume a patch for another version is interchangeable.

3. Apply the September security updates as well

CVE-2026-75650 is not the only issue in the September security cycle.

Adobe's APSB26-138 bulletin addresses additional vulnerabilities, and Adobe says to apply the CVE-2026-75650 hotfix in addition to the September security updates.

The goal is to bring the installation to the correct security state for its exact version.

Adobe's remediation guidance also calls for rotating the encryption key and relevant credentials that may have been exposed.

That can include:

  • Server credentials
  • API and integration credentials
  • Payment-related credentials
  • System-privileged automation tokens

Patching alone does not make previously exposed secrets safe.

5. Verify That the Hotfix Is Actually Applied

Do not assume a deployment succeeded simply because a patch command ran.

Adobe provides a way to verify the hotfix status with the Quality Patches Tool. The exact verification depends on your environment, but the important result is that the relevant hotfix should show as Applied.

Adobe: Urgent Action Required for APSB26-146

Does This Mean You Need to Rebuild Your Magento Store?

No.

A security vulnerability does not automatically mean:

“Replace Magento.”

The first priority is to secure the existing installation.

A rebuild, upgrade or migration becomes a separate architectural decision.

It may be worth considering when:

  • The Magento version is difficult to support.
  • Security updates repeatedly require risky manual work.
  • Custom modules are heavily outdated.
  • Core files have been modified.
  • The store has accumulated substantial technical debt.
  • Performance or maintainability is already a business problem.
  • The current architecture cannot support upcoming requirements.

In other words:

Patch first. Then decide whether the platform itself needs a bigger change.

For background on when a business should redesign, rebuild or migrate, see Website Redesign vs Rebuild vs Migration.

A Practical Checklist

Before considering the issue closed, confirm:

  • Exact Magento / Adobe Commerce version and patch level identified
  • CVE-2026-75650 hotfix applied as appropriate
  • September 2026 security updates applied
  • Encryption key and relevant credentials rotated where required
  • Production deployment verified
  • Checkout and critical integrations tested
  • Hotfix status confirmed

Keep a record of what was applied and when.

What CorgenX Can Help With

Magento security work is not always as simple as applying a patch.

A production ecommerce store may have custom modules, payment integrations, ERP connections, theme modifications and deployment constraints that need to be considered.

CorgenX works on eCommerce development, Magento, performance, migration and website modernization.

For a security remediation project, the first step should be understanding the current installation:

What version are you running?

What has already been patched?

What custom code and integrations are involved?

What is the safest remediation path?

Sometimes the answer is a focused patch.

Sometimes it is a larger upgrade.

And sometimes the security issue reveals a wider modernization or migration requirement.

Explore eCommerce Development

Explore Website Migration

Official Adobe Sources

Final Takeaway

If you run Magento Open Source or Adobe Commerce, do not treat this as a routine maintenance item.

Adobe says CVE-2026-75650 is critical, can allow unauthenticated arbitrary code execution, and is being exploited in the wild.

The right response is straightforward:

Identify → Patch → Rotate → Verify → Test.

And only after the store is secure should you ask the larger question:

Is the current Magento architecture still the right fit for the business?

Security comes first. Architecture comes next.

Share this article

Back to all articles

Contact Us

Have a Website or Digital Project in Mind?

Tell us what you're trying to build, improve, migrate or scale. We'll understand the requirement and recommend the right approach.

Get a Free Website Audithello@corgenx.com

Fill in your details and we’ll reach out to you within 24h