Skip to content

Build1 publisher2 min readPublished

Confirmed exploitation moves the Adobe Commerce RCE to the front of CERT-In's patch queue

CERT-In's September 16 advisory covers eleven Adobe product lines and fourteen vulnerability classes. Adobe says one of them, an unauthenticated remote code execution flaw in the commerce line, is already being exploited.

The Engineer · Build desk

Illustration accompanying Confirmed exploitation moves the Adobe Commerce RCE to the front of CERT-In's patch queue

What happened

  • CERT-In published vulnerability note CIVN-2026-0458 on September 16, 2026 and rated it critical, covering multiple vulnerabilities across eleven Adobe product lines including Experience Manager, ColdFusion, Acrobat and Campaign Classic.
  • CVE-2026-75650 is a critical remote code execution flaw in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that an unauthenticated remote attacker can exploit.
  • Adobe has confirmed the flaw is being exploited in the wild, one of three properties the CERT-In note states for this entry specifically.
  • A ZoomEye search on the Magento application fingerprint returned 132,158 assets, while the query for hosts tagged with the CVE identifier returned zero.
  • The dev.to write-up argues the missing authentication requirement and the confirmed exploitation together make this the first item to close in the bulletin.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision If the maintenance window cannot absorb eleven product lines at once, there is now a defensible first item, and the rest of the bulletin waits behind it.
  • exposure Answering unauthenticated requests is a storefront's normal function, so the attacker's only precondition is met by every store that is open for business.
  • cost The update is one part of the work: whoever runs the store also pays for a compromise review, and that labour was not in the sprint.
  • constraint Scoping a fleet cannot lean on the scanner's CVE tag, which leaves an internal inventory of installed commerce builds as the only reliable filter.

Unauthenticated is a statement about preconditions, and it is what makes this entry rankable against the rest. An attacker needs a network route to the store and a build inside the affected range [5][7]. The credential step that usually sits in front of remote code execution is absent, and the storefront publishes that route deliberately.

Ordering the rest of the advisory is harder. The note lists fourteen vulnerability classes over eleven product lines without mapping class to product [16][17][19]. Improper authorization and OS command injection sit in the same undifferentiated set as prototype pollution [3].

For the commerce line the version test is short. CERT-In lists Adobe Commerce 2.4.4-2026-aug through 2.4.9-2026-aug and earlier, Adobe Commerce B2B 1.3.3-2026-aug through 1.5.3-2026-aug and earlier, and Magento Open Source 2.4.6-2026-aug through 2.4.9-2026-aug and earlier [7][8][9]. Every one of those three ranges ends in "and earlier" [20]. That puts any install off the patched August 2026 build in scope until an inventory proves otherwise.

The commerce fix arrives as two bulletin ids, apsb26-138 and apsb26-146 [11], so a change ticket built from a single Magento bulletin may still have work left in it. For the other lines the note names one each: apsb26-98 for Experience Manager, apsb26-119 for ColdFusion, apsb26-141 for Acrobat, apsb26-142 for Campaign Classic [10].

The exposure figure counts Magento fingerprints. For it to describe a given fleet, the store would have to answer an internet scan with something the indexer labels Magento [12]. The query also lumps Adobe Commerce in with Magento Open Source, and patched builds in with unpatched ones. The identifier query returned zero hosts, which the dev.to post attributes to indexing lag [13].

Confirmed exploitation changes what the patch closes out. Adobe's position is that attacks are already happening against these versions [6]. The dev.to post recommends prioritising internet-facing commerce deployments and following the update with a compromise review [15].

What to watch

  • ZoomEye's CVE tag populating for CVE-2026-75650, which would replace a platform-wide fingerprint count with a scoped host count.
  • Per-CVE detail for the other thirteen vulnerability classes, which would let teams order the remainder of CIVN-2026-0458 on something other than product name.
  • Published exploitation detail such as entry point or indicators, which would tell store operators what the recommended compromise review should look for.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories