Adobe issued security updates for multiple vulnerabilities in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, including CVE-2026-71362, which open-source reporting indicates is being actively exploited in the wild. The broader advisory also covers Adobe Campaign Classic, ColdFusion, Content Credentials tools and SDKs, and Lightroom Classic.
The Commerce flaws are remotely exploitable and may enable arbitrary code execution, malicious script injection into web forms, disclosure of sensitive information, security-control bypasses, privileged access to restricted files, and temporary denial of service. NCSC Netherlands, Guyana CIRT, and bjCSIRT urged administrators to apply Adobe's updates immediately; NCSC reported no known public proof-of-concept or exploit code for the vulnerabilities it described.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-75650 was published as a critical remotely exploitable Adobe Commerce B2B vulnerability. Its CVSS v3 vector indicates network exploitation requiring no privileges or user interaction, with high confidentiality, integrity, and availability impact and changed scope; Adobe published an associated patch on September 7, 2026.
Open-source reporting cited in the Adobe advisory coverage indicated that CVE-2026-71362 was being exploited in the wild.
The Canadian Centre for Cyber Security published its Adobe security advisory, identified as AV26-808.
Adobe published a security advisory addressing vulnerabilities affecting Adobe Commerce, Magento Open Source, ColdFusion, Campaign Classic, Lightroom Classic, and Content Credentials tools and SDKs. The advisory identified affected versions through August 2026 and provided updates for affected products, including Adobe Commerce.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
csirt.bj
Open sourcetenable.com
Open sourcencsc.nl
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.