The Wider Adobe Patch Wave Behind CVE-2026-75650
CVE-2026-75650 is the entry in CERT-In's CIVN-2026-0458 that demands immediate action, but it is not the only vulnerability in the advisory. Understanding the surrounding patch wave helps teams sequence the work and avoid treating the whole document as a single, undifferentiated task.
The advisory at a glance
CERT-In published CIVN-2026-0458 on September 16, 2026, rating it CRITICAL. It covers multiple vulnerabilities across Adobe Experience Manager, ColdFusion, Photoshop, Illustrator, Animate, Photoshop Mobile, Adobe Commerce, Magento Open Source, Acrobat, Acrobat Reader and Campaign Classic.
The vulnerability classes listed include improper authorization, cross-site scripting, improper input validation, code injection, SQL injection, path traversal, out-of-bounds memory access, use-after-free, prototype pollution, integer overflow, heap-based buffer overflow, improper access control, uncontrolled resource consumption and OS command injection.
Why CVE-2026-75650 leads the queue
Within that set, CVE-2026-75650 is distinguished by three properties the note states directly. It affects Adobe Commerce, Adobe Commerce B2B and Magento Open Source. It is a critical remote code execution vulnerability exploitable by an unauthenticated remote attacker. And Adobe has confirmed it is being exploited in the wild.
The other vulnerabilities in the advisory may be equally severe in isolation, but the confirmed exploitation and the absence of an authentication requirement make this one the first item to close.
Affected commerce versions
- Adobe Commerce 2.4.4-2026-aug through 2.4.9-2026-aug and earlier.
- Adobe Commerce B2B 1.3.3-2026-aug through 1.5.3-2026-aug and earlier.
- Magento Open Source 2.4.6-2026-aug through 2.4.9-2026-aug and earlier.
The rest of the wave
The same advisory lists affected versions for Adobe Experience Manager (Cloud Service release 2026.7.0 and earlier, 6.5 LTS Service Pack 2 and earlier, 6.5 Service Pack 24 and earlier), ColdFusion (2025.0.12 and earlier, 2023.0.23 and earlier), Photoshop, Illustrator, Animate, Photoshop Mobile, Acrobat and Acrobat Reader (Continuous 26.002.21900 and earlier, 2024 Classic 24.001.30383 and earlier) and Campaign Classic (ACC v7 7.4.4 build 9401 and earlier).
CERT-In provides separate vendor bulletins for each product line, including apsb26-98 for Experience Manager, apsb26-119 for ColdFusion, apsb26-141 for Acrobat and apsb26-142 for Campaign Classic.
Exposure context
A ZoomEye query for app="Magento" returned 132,158 assets, giving a sense of how widely the commerce platform is exposed. The identifier query vul.cve="CVE-2026-75650" returned zero, which reflects indexing lag rather than absence of vulnerable hosts.
Remediation
Apply the vendor updates referenced in the advisory. For the commerce line, that means apsb26-138 and apsb26-146. For the remaining products, use the corresponding bulletin. Because CVE-2026-75650 is confirmed exploited, prioritise internet-facing commerce deployments and follow the patch with a compromise review.
References
- CERT-In Vulnerability Note CIVN-2026-0458 (September 16, 2026): https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0458
- Adobe Experience Manager bulletin apsb26-98: https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html
- Adobe ColdFusion bulletin apsb26-119: https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html
- Adobe Acrobat bulletin apsb26-141: https://helpx.adobe.com/security/products/acrobat/apsb26-141.html
- Adobe Campaign bulletin apsb26-142: https://helpx.adobe.com/security/products/campaign/apsb26-142.html
- Adobe Magento bulletins apsb26-138 and apsb26-146: https://helpx.adobe.com/security/products/magento/apsb26-138.html
Top comments (0)