The Australian Cyber Security Centre (ACSC) has issued a warning regarding the active exploitation of a critical vulnerability in Adobe Commerce and Magento Open Source. This alert is particularly relevant for Australian organizations utilizing these platforms, as a significant number of potentially vulnerable instances have been identified within the local economy. System owners are urged to take immediate action based on the vendor’s mitigation advice.
Vulnerability Overview
Adobe has disclosed a critical vulnerability, tracked as CVE-2026-75650, affecting its Adobe Commerce and Magento Open Source platforms. This vulnerability stems from an improper neutralization of special elements used in a template engine, which can lead to unauthenticated remote code execution. Notably, exploitation of this vulnerability requires that the /graphql endpoint be exposed.
A patch addressing this issue was released on September 7, 2026. Organizations are strongly advised to apply this patch as a priority. For those using unpatched versions, it is crucial to update to a version that includes this fix without delay.
Mitigation Strategies
The ACSC recommends that organizations take the following steps to mitigate the risk associated with this vulnerability:
- Conduct a thorough review of networks and environments to identify any instances of vulnerable Adobe platforms.
- Consult the mitigation advice available on the vendor support page.
- If your Adobe Commerce or Magento Open Source platform is managed by a third-party service provider, contact them to confirm that the necessary patches have been applied and that systems are being monitored for suspicious activity.
- Apply the patches as soon as possible. If a patch is not available for your version, consider the following actions:
- Update to a version that includes the patch.
- Restrict and monitor access, and keep an eye out for unusual system activity, unexpected scheduled tasks, and suspicious log entries, which may indicate attempts at exploitation.
- Report any detected suspicious activity to the ACSC.
Organizations that suspect they have been impacted or require further assistance can reach out to the ACSC at 1300 CYBER1 (1300 292 371).
For more detailed information on this vulnerability and the associated risks, please refer to the ACSC’s advisory here.
Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.



