Critical Adobe Commerce and Magento Flaw Under Active Attack: Patch Now
The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has issued an alert about active exploitation of a critical vulnerability affecting Adobe Commerce and Magento Open Source, two widely used PHP-based e-commerce platforms that power online stores. The ACSC says a substantial number of potentially vulnerable systems exist within the Australian economy, making this a priority issue for any business running these platforms.
The flaw, tracked as CVE-2026-75650, allows attackers to run malicious code on a vulnerable system without needing to log in first. It relates to how the platform's template engine handles certain inputs, and exploitation requires the site's /graphql endpoint to be exposed. Adobe released a patch on 7 September 2026, and the ACSC is urging all organisations running unpatched versions to update immediately.
While the ACSC has not identified a specific industry or sector being targeted, active exploitation means any exposed online store using these platforms is at risk. Businesses relying on e-commerce hosting providers or agencies should confirm with them directly that patching has been completed.