CISA confirms active attacks on Adobe Commerce and Magento flaw — but details are scarce

A newly catalogued Adobe Commerce and Magento bug is already being exploited, says CISA, though it's telling us very little about how.

What’s actually confirmed

The US Cybersecurity and Infrastructure Security Agency has added a flaw in Adobe Commerce and Magento — tracked as CVE-2026-75650 — to its Known Exploited Vulnerabilities catalogue, the list CISA maintains for bugs it has evidence are being used in real attacks, not just theoretical weaknesses sitting in a lab report.

That’s the key fact here: this isn’t a “researchers found a bug” story, it’s a “someone is already using this against real websites” story. CISA added the entry on 8 September 2026 and has given US federal agencies until 11 September 2026 to apply mitigations — a three-day window that signals the agency views this as urgent rather than routine.

Beyond that, though, the publicly available detail is thin. CISA’s own listing doesn’t specify what the vulnerability actually does — whether it allows remote code execution, lets attackers bypass authentication, or something else entirely. It also marks the “known ransomware use” field as unknown, meaning there’s no confirmed link to ransomware campaigns, but that’s a “we don’t know” rather than a “we’ve ruled it out”. Adobe’s own advisory and the NVD entry should carry a fuller technical breakdown and severity score once populated, and that’s worth checking directly if you run affected infrastructure — this article deliberately isn’t speculating on mechanics the sources don’t confirm.

So who is actually at risk

Adobe Commerce and Magento are e-commerce platforms — the software that powers online shopfronts, not something sitting on your laptop or phone. If you’ve never run an online store, this bug has no direct bearing on you.

The people who need to pay attention are businesses and developers running Adobe Commerce or Magento installations, particularly self-hosted ones where patching is the site operator’s own responsibility rather than something handled invisibly by a cloud provider. Federal agencies are named specifically because CISA’s directive only has legal force over US government systems, but the same urgency logically applies to any organisation running the software, government or not.

Ordinary shoppers are only indirectly affected, and only if a retailer they use happens to be running a vulnerable, unpatched Magento or Commerce instance that gets compromised. There’s no indication in CISA’s listing of which retailers, if any, have already been hit, or how many sites are exposed.

What to do about it

If you administer an Adobe Commerce or Magento deployment, the sensible move is the boring one: check Adobe’s security bulletins for CVE-2026-75650 and apply whatever patch or mitigation they’ve published, rather than waiting for more detail to trickle out. CISA’s guidance points administrators towards its BOD 26-04 update-prioritisation framework, which is really just a formal way of saying “patch known-exploited bugs first, deprioritise the rest.”

For everyone else, there’s genuinely nothing to do. This is an infrastructure story, not a consumer one — no app to update, no password to change on the strength of this alone.

The takeaway

A real, actively exploited vulnerability in a widely used e-commerce platform is worth flagging, and CISA’s KEV listing is a solid basis for that. But the specifics — how it’s exploited, how widely, and by whom — aren’t public yet, so treat the alarm as proportionate to what’s confirmed: site operators should patch promptly, and shoppers can carry on as normal.

Sources