132,792 Matches for Magento and 10.0 CVSS: Sizing the Commerce Surface Behind CVE-2026-75650
A commerce platform population that maps directly to attacker value
CVE-2026-75650 is a template engine vulnerability in Adobe Commerce and Magento Open Source with a CVSS 3.1 base score of 10.0. CISA added it to the Known Exploited Vulnerabilities catalog on 8 September 2026 with a due date of 11 September.
Two ZoomEye queries bound the surface. app="Magento" returns 132,792 matches. app="Adobe Commerce" returns zero. Both ran on 24 September 2026 with sub_type=all and a page size of one.
Reading a zero and a large number together
The zero is informative. Adobe Commerce deployments frequently do not present a distinguishable fingerprint, either because the storefront is behind a proxy, because the banner matches the Magento fingerprint instead, or because the commercial edition shares enough of the codebase that identification resolves to the open source pattern.
The practical consequence is that app="Magento" is the more useful query for both editions. 132,792 is the number to work with, and it understates the population because it counts only instances that answer an external query with an identifiable signature.
Why commerce counts carry more risk per host
A storefront holds payment integration credentials, customer records, order history and API keys for shipping, tax and ERP systems. Code execution on that platform reaches all of it, which is why a CVSS 10.0 with no user interaction required is treated as urgent rather than academic.
The template engine sits inside the rendering path, so the exposure depends on what is installed alongside the core. Themes and extensions that introduce their own templates widen the reachable surface beyond what a version check will show.
What to do with the measurement
Apply the patches from Adobe bulletin APSB26-146, then audit themes and extensions for custom template logic, because a patched core does not remove an insecure extension. Inspect the file tree for web shells and recently modified files under writable directories.
Query your own address space for both fingerprints. Where a storefront answers externally, confirm it should. A commerce administration interface reachable from the internet is a separate finding from the CVE, and often an easier one to close.
Re-measure after remediation to confirm the storefront is running the patched build rather than a staging deployment.
Notes on scope and method
Queries: app="Magento" and app="Adobe Commerce". Collection time: 2026-09-24 02:36 UTC. Scope: all asset types, page size 1. The zero result for Adobe Commerce reflects fingerprint identification, not the absence of Adobe Commerce deployments.
References
- NVD, CVE-2026-75650: https://nvd.nist.gov/vuln/detail/CVE-2026-75650
- Adobe security bulletin APSB26-146: https://helpx.adobe.com/security/products/magento/apsb26-146.html
- CISA Known Exploited Vulnerabilities Catalog, CVE-2026-75650: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650
- ZoomEye: https://www.zoomeye.ai/
Top comments (0)