First published: 09 Sep 2026
Last updated: 09 Sep 2026

Content written for

Small & medium business
Large organisations & infrastructure
Government

The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) is aware of reported active exploitation of a critical vulnerability in Adobe Commerce and Magento Open Source.

ASD’s ACSC is aware of a substantial number of potentially vulnerable instances within the Australian economy and encourage system owners to follow the mitigation advice from the vendor.

This alert is relevant to all Australian organisations that utilise Adobe Commerce and Magento Open Source. 

This alert is intended for a technical audience.

Background

Adobe has identified a critical vulnerability affecting the Adobe Commerce and Magento Open Source platform.

Adobe Commerce and Magento Open Source are PHP-based e-commerce platforms used to power online storefronts.

CVE-2026-75650 is an Improper Neutralisation of Special Elements Used in a Template Engine vulnerability, leading to unauthenticated remote code execution. Exploitation requires the /graphql endpoint to be exposed.

A patch was released on 7 September 2026. Organisations should apply the patch as a priority. If using an unpatched version, organisations should update their version that includes this patch as a priority.

ASD's ACSC is aware of reported active exploitation of this vulnerability, but has no information to indicate that a specific industry or sector is being targeted.

Mitigation advice

ASD's ACSC advises organisations to ensure the following:

  • Review networks and environments for use of vulnerable versions of the Adobe platform.
  • Review the mitigation advice on the vendor support page.
  • If your Adobe Commerce and Magento Open Source platform is managed by a third party, such as a MSP or Enterprise IT provider, you should contact that provider to ensure the products have been patched and are being monitored for suspicious activity.
  • Apply patches as soon as practicable, if required. If a patch is not available for the version you use: 
    • Update to a version that includes this patch, or
    • Restrict and monitor access, monitor for unusual system activity, unexpected scheduled tasks, and suspicious log entries such as unusual template processing or failed notifications, as these may indicate an attempted exploitation.
  • If suspicious activity is detected, notify ASD’s ACSC.

Where to get help

Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371)

Was this helpful?
Yes this was helpful
No this was not helpful

Thanks for your feedback!

We welcome additional feedback below.

Was this information easy to understand?
Will you take action after reading this?
Did you find the information you were looking for?
Did the design and layout of this page meet your expectations?