Security News

Critical Adobe Commerce and Magento Flaw Under Active Attack: Patch Now

Key Takeaway If your business runs an Adobe Commerce or Magento Open Source store, apply the September 2026 patch immediately and check with your hosting or development provider that it has been done.

The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has issued an alert about active exploitation of a critical vulnerability affecting Adobe Commerce and Magento Open Source, two widely used PHP-based e-commerce platforms that power online stores. The ACSC says a substantial number of potentially vulnerable systems exist within the Australian economy, making this a priority issue for any business running these platforms.

The flaw, tracked as CVE-2026-75650, allows attackers to run malicious code on a vulnerable system without needing to log in first. It relates to how the platform's template engine handles certain inputs, and exploitation requires the site's /graphql endpoint to be exposed. Adobe released a patch on 7 September 2026, and the ACSC is urging all organisations running unpatched versions to update immediately.

While the ACSC has not identified a specific industry or sector being targeted, active exploitation means any exposed online store using these platforms is at risk. Businesses relying on e-commerce hosting providers or agencies should confirm with them directly that patching has been completed.

Adobe Commerce Magento e-commerce security vulnerability ACSC alert

Summarised by CISO AI from Australian Cyber Security Magazine. We link back to every original so you can read it yourself.