Menu

Magento and Adobe Commerce stores under attack: ACSC issues a critical alert

Comingwave team · 6 minute read · published

An online retailer checks a laptop at a packing bench surrounded by parcels in a small warehouse.

Magento and Adobe Commerce online stores are being attacked through a critical vulnerability, and on 21 September 2026 the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) issued a critical alert about it. The flaw, CVE-2026-75650, lets an attacker run their own code on a store's server without logging in. Adobe released a fix on 7 September. The ACSC says it is aware of a substantial number of potentially vulnerable stores in Australia, so any business that sells online with either platform should confirm this week that the fix is in place.

What the ACSC alert says

The ACSC alert on active exploitation of Adobe Commerce and Magento Open Source is rated "Critical", a status the agency uses for vulnerabilities where organisations should take immediate action to minimise the risk. Its main points are:

  • ASD's ACSC is aware of reported active exploitation of a critical vulnerability in Adobe Commerce and Magento Open Source.
  • It is aware of "a substantial number of potentially vulnerable instances within the Australian economy".
  • CVE-2026-75650 is a template engine flaw that leads to unauthenticated remote code execution.
  • Exploitation requires the store's /graphql endpoint to be exposed.
  • A patch was released on 7 September 2026 and should be applied as a priority.
  • The ACSC has no information to indicate that a specific industry or sector is being targeted.

The alert applies to every Australian organisation that uses the two platforms, whatever its size.

What Adobe's bulletin confirms

Adobe's own notice is security bulletin APSB26-146. It states plainly that Adobe is aware of CVE-2026-75650 being exploited in the wild.

ItemWhat Adobe's bulletin says
BulletinAPSB26-146, published 7 September 2026
Priority rating1
VulnerabilityCVE-2026-75650, improper neutralisation of special elements used in a template engine
ImpactArbitrary code execution
SeverityCritical, CVSS base score 10.0
Login needed to exploitNo
FixA hotfix for CVE-2026-75650, for Adobe Commerce and Magento Open Source

The affected versions listed by Adobe are:

  • Adobe Commerce: 2.4.9-2026-aug and earlier, and the equivalent August 2026 releases and earlier on the 2.4.8, 2.4.7, 2.4.6, 2.4.5 and 2.4.4 lines.
  • Adobe Commerce B2B: 1.5.3-2026-aug and earlier, 1.5.2-2026-aug and earlier, 1.4.2-2026-aug and earlier, 1.3.4-2026-aug and earlier, and 1.3.3-2026-aug and earlier.
  • Magento Open Source: 2.4.9-2026-aug and earlier, and the equivalent releases and earlier on the 2.4.8, 2.4.7 and 2.4.6 lines.

In short, if a store has not been updated since the fix came out on 7 September, assume it is affected until someone has checked.

What the technical terms mean

Unauthenticated remote code execution

"Remote code execution" means an attacker can make the server run commands of their choosing over the internet. "Unauthenticated" means they do not need a username or password first. Adobe gives the flaw a CVSS base score of 10.0, the maximum on that scale. A web server that runs an attacker's commands can no longer be trusted to protect what it holds, and for an online store that includes customer names, addresses and order histories.

The /graphql endpoint

GraphQL is a way for the storefront, mobile apps and other systems to request data from the store. The /graphql address is where those requests are sent. The ACSC notes that exploitation requires this endpoint to be exposed.

The gap between patch and alert

Adobe published the fix on 7 September and the ACSC raised its alert two weeks later. Stores patched promptly had far less exposure than those still waiting. Neither Adobe nor the ACSC has named affected organisations or said who is behind the activity, and this article does not speculate.

Who is at risk

Any business running Adobe Commerce or Magento Open Source on an affected version: a homewares retailer with a single storefront, a wholesaler with a trade ordering portal on Adobe Commerce B2B, or a hospitality group selling vouchers online. The ACSC describes both products as PHP-based e-commerce platforms used to power online storefronts. A store is often built and hosted by an outside agency, so some owners may not know which platform sits behind their site. If you are unsure, your web developer or hosting company can tell you in one email.

Stores built years ago and left alone are the main concern. A site that still takes orders every day can easily go without updates when the agency that built it has moved on and nobody was given the job of maintaining it.

What to do this week

These steps follow the mitigation advice in the ACSC alert.

  1. Find out what you run. Ask your developer, agency or host which platform and exact version your store uses, and compare it with Adobe's affected list.
  2. Apply Adobe's hotfix. The ACSC says to apply patches as soon as practicable. If the hotfix is not available for your version, update to a version that includes it.
  3. Get confirmation from third parties. If an agency, managed service provider or host manages the store, the ACSC advises contacting them to ensure it has been patched and is being monitored for suspicious activity. Ask for the date the hotfix was applied.
  4. If you cannot patch yet, restrict and monitor. The ACSC's fallback is to restrict and monitor access, and to watch for unusual system activity, unexpected scheduled tasks, and suspicious log entries such as unusual template processing or failed notifications.
  5. Check for signs of compromise. The flaw was being exploited while stores were unpatched, so patching alone does not tell you whether someone got in first. Have server logs, administrator accounts, scheduled tasks and recently changed files reviewed.
  6. Report suspicious activity. The ACSC asks organisations to notify it, and offers help on 1300 CYBER1 (1300 292 371).
  7. Consider your privacy obligations. If customer information may have been accessed, the OAIC's Notifiable Data Breaches scheme requires organisations covered by the Privacy Act to notify affected individuals and the OAIC when a breach is likely to result in serious harm. Get advice early.

After the emergency

The ACSC's small business guidance, Secure your website, lists the habits that prevent the next scramble: multi-factor authentication on website administrator accounts, HTTPS, strong passwords and sensible access controls, regular backups of website data, keeping software and plugins up to date, and reviewing the site for suspicious activity. The lesson from this alert is ownership. Every online store needs a named person or provider who receives vendor security bulletins and is responsible for acting on them.

Comingwave is a technology company that provides cyber security, cloud migration and hosting and managed IT support to small and medium businesses. If your store has no one looking after updates and monitoring, request a free first consultation or a written quote.

Key takeaways

  • ASD's ACSC issued a critical alert on 21 September 2026 for CVE-2026-75650 in Adobe Commerce and Magento Open Source.
  • Adobe says the flaw is being exploited in the wild, needs no login and scores 10.0 on the CVSS scale.
  • Adobe released a hotfix on 7 September 2026 in bulletin APSB26-146.
  • The ACSC is aware of a substantial number of potentially vulnerable instances in Australia.
  • Patch, confirm with whoever manages the store, check for signs of compromise and report anything suspicious.

Frequently asked questions

What is CVE-2026-75650?

It is a critical vulnerability in Adobe Commerce and Magento Open Source. Adobe describes it as improper neutralisation of special elements used in a template engine, and says it allows arbitrary code execution with no authentication required.

Which versions of Adobe Commerce and Magento are affected?

Adobe lists Adobe Commerce 2.4.9-2026-aug and earlier across the 2.4.4 to 2.4.9 lines, Magento Open Source 2.4.9-2026-aug and earlier across the 2.4.6 to 2.4.9 lines, and several Adobe Commerce B2B releases. Check the bulletin for your exact version.

An agency hosts and manages our store. Do we still need to act?

Yes. The ACSC advises organisations whose platform is managed by a third party to contact that provider and ensure the product has been patched and is being monitored. Ask for written confirmation and the patch date.

Does this alert affect stores on other e-commerce platforms?

The ACSC alert and Adobe's bulletin name only Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Stores on other platforms are not covered by this alert, though the same habit of prompt updates applies to them.

What should we do if we find signs of compromise?

Preserve the logs, involve your developer or IT provider, and notify ASD's ACSC, which can be contacted on 1300 CYBER1 (1300 292 371). If personal information may be involved, seek advice on your notification obligations.

Need help with your business technology?

Tell us what you need. We reply within one business day.

Get a free quote