Urgent: Critical Adobe Commerce Zero-Day (CVE-2026-75650) — What Australian Magento Merchants Need to Do Now

Quick answer: On 7 September 2026, Adobe confirmed a critical zero-day vulnerability, CVE-2026-75650, is being actively exploited in the wild against Adobe Commerce and Magento Open Source stores. It could let an unauthenticated attacker execute arbitrary code on an affected store. If you run Adobe Commerce, Adobe Commerce B2B, or Magento Open Source on any version up to and including 2.4.9-2026-aug, you need to apply Adobe’s hotfix (Security Bulletin APSB26-146) and rotate your credentials immediately — not at your next scheduled maintenance window.

If you run a Magento or Adobe Commerce store in Australia, this is one of the more serious security events of the year, and it deserves urgent attention rather than a routine patch cycle.

What Happened?

Adobe became aware of a zero-day vulnerability in Adobe Commerce and released Security Bulletin APSB26-146 on 7 September 2026 to address it. Unlike most Patch Tuesday-style updates, Adobe explicitly confirmed active exploitation, meaning attackers were already using this vulnerability against real merchant stores before the fix was released. That combination — zero-day plus confirmed in-the-wild exploitation — is what pushes this from “patch when convenient” to “patch today.”

The following day, 8 September 2026, Adobe also released its regularly scheduled monthly security update, APSB26-138, addressing a separate set of critical, important, and moderate vulnerabilities. Store owners applying the September fixes need to account for both bulletins, not just the zero-day.

This follows two other significant Adobe Commerce security bulletins earlier in the year — APSB26-73 in July and APSB26-92 in August — making September the third major patch cycle in three months. If your store’s patching has fallen behind at any point this year, it’s worth assuming you’re currently exposed.

Who Is Affected?

The vulnerability, tracked as CVE-2026-75650, affects a wide version range across all three Adobe Commerce product lines:

Adobe Commerce: versions 2.4.9-2026-aug and earlier, including 2.4.8, 2.4.7, 2.4.6, 2.4.5, and 2.4.4 branches

Adobe Commerce B2B: versions 1.5.3, 1.5.2, 1.4.2, 1.3.4, and 1.3.3, and earlier

Magento Open Source: versions 2.4.9-2026-aug and earlier, including 2.4.8, 2.4.7, and 2.4.6 branches

In practical terms: unless you’ve applied the September 2026 hotfix, your store is very likely vulnerable, regardless of which 2.4.x branch you’re running.

What Could Happen If You Don’t Patch?

Adobe describes the vulnerability as allowing an unauthenticated attacker to execute arbitrary code on an affected installation. In plain terms, this means someone doesn’t need a login or admin access to potentially take control of parts of your store’s backend — they can exploit the flaw directly. Given Adobe has confirmed real-world exploitation, this isn’t a theoretical risk sitting in a lab report; it’s an active threat already being used against live stores.

For an Australian retailer, the consequences of a successful exploit can include stolen customer and payment data, defaced or hijacked storefronts, malicious code injected into checkout flows (a classic Magecart-style attack), and significant downtime while you clean up and rebuild trust — on top of potential breach notification obligations under Australian privacy law.

How to Fix It: Step-by-Step

Adobe has published a specific hotfix for CVE-2026-75650 (internally referenced as VULN-39341), with different patch files depending on your exact version. Here’s the recommended remediation path:

  1. Identify your exact Adobe Commerce or Magento Open Source version, including patch level (e.g. 2.4.7-p8 vs 2.4.7-p9).
  2. Download the correct hotfix patch file for your version from Adobe’s official patch repository — the file differs depending on whether you’re on, for example, 2.4.8-p3, 2.4.7-p8, or the newer “2026-aug” cloud release lines.
  3. Apply the patch in a staging environment first, confirming it doesn’t conflict with custom code, extensions, or Hyvä/theme customisations.
  4. Deploy to production once verified, following Adobe’s standard composer patch process.
  5. Confirm the patch is actually applied — Adobe notes this isn’t always obvious from the outside, and recommends using the Quality Patches Tool to verify the patch status directly rather than assuming a deployment succeeded.
  6. Rotate your encryption key and all associated credentials. This is the step many merchants skip, and Adobe is explicit that it’s required for full remediation — the encryption key protects integration tokens, payment gateway credentials, and automation tokens, and simply reapplying the patch does not invalidate anything that may already have been exposed.

Full Credential Rotation Checklist

Once the hotfix is applied, Adobe recommends rotating, in order: your encryption key, all Admin panel user passwords, every REST/SOAP/GraphQL integration token, OAuth client secrets for connected third-party apps, payment gateway API credentials at the provider level (Stripe, Braintree, Adyen, PayPal, etc.), database credentials, and SSH/deploy keys or system-privileged service account credentials, plus API keys for any integrated shipping, tax, or third-party extensions.

This is a genuinely involved process — enabling maintenance mode, disabling cron, rotating each credential type in the correct order, then re-enabling cron and redeploying — and it’s easy to miss a step under time pressure, which is exactly when mistakes introduce new downtime or broken integrations.

Should You Handle This Yourself or Call In Help?

If you have an in-house development team comfortable with Composer patches, staging environments, and Adobe Commerce’s credential architecture, you can follow Adobe’s official remediation steps directly. If you don’t — or if your last patch cycle happened more than a few months ago — this is exactly the kind of urgent, high-stakes patching that’s worth handing to a specialist team, precisely because a rushed or incomplete credential rotation can leave gaps that look fixed but aren’t.

Frequently Asked Questions

What is CVE-2026-75650? It’s a critical zero-day vulnerability in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, disclosed by Adobe on 7 September 2026 via Security Bulletin APSB26-146, that allows an unauthenticated attacker to execute arbitrary code on an affected store.

Is this vulnerability actively being exploited? Yes. Adobe has explicitly confirmed CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants, which is why it’s classified as an urgent, immediate-action item rather than a routine update.

Which Magento and Adobe Commerce versions are affected? Adobe Commerce 2.4.4 through 2.4.9 (including all “-2026-aug” and prior patch releases), Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.4 through 2.4.9, all up to their pre-September-2026 patch levels.

Is applying the patch enough, or do I need to do more? Applying the hotfix alone is not considered full remediation. Adobe explicitly recommends rotating your encryption key and all related credentials afterward, since the patch itself doesn’t invalidate anything that may have already been compromised.

How urgent is this really? Very. Combining a zero-day disclosure with confirmed active exploitation is one of the most serious classifications Adobe issues. If your store hasn’t been patched since before 7 September 2026, treat this as immediate priority, not a task for your next sprint.

Final Thoughts

Zero-day vulnerabilities with confirmed exploitation are rare enough that when one lands on a platform running a large share of the world’s online stores, it deserves genuine urgency, not a “we’ll get to it” response. If your Magento or Adobe Commerce store hasn’t had the September 2026 patches applied and full credential rotation completed, that gap is the priority for this week, not next month.

If you’d like a fast, verified patch-and-rotate on your store, our team can apply the CVE-2026-75650 hotfix, confirm it’s genuinely in place, and manage the full credential rotation process safely, without disrupting your live storefront.