The Wider Adobe Patch Wave Behind CVE-2026-75650
The Wider Adobe Patch Wave Behind CVE-2026-75650 CVE-2026-75650 is the entry in CERT-In's CIVN-2026-0458 that demands immediate action, but it is not the only vulnerability in the advisory. Understanding the surrounding patch wave helps teams sequence the work and avoid treating the whole document as a single, undifferentiated task. The advisory at a glance CERT-In published CIVN-2026-0458 on…
CERT-In issued a critical CVE-2026-75650 advisory on September 16, 2026, highlighting multiple vulnerabilities across Adobe's suite of products. While the advisory details numerous issues, CVE-2026-75650 stands out as the most pressing, demanding immediate remediation. This vulnerability is a remote code execution flaw in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, exploitable by unauthenticated attackers.
Adobe has confirmed instances of exploitation in the wild, making it a critical priority. Other vulnerabilities in the advisory, while severe, require authentication and aren't being actively exploited. Affected versions span Adobe Commerce 2.4.4-2026-aug through 2.4.9-2026-aug, Adobe Commerce B2B 1.3.3-2026-aug through 1.5.3-2026-aug, and Magento Open Source 2.4.6-2026-aug through 2.4.9-2026-aug.
The Adobe Experience Manager, ColdFusion, Photoshop, Illustrator, Animate, Photoshop Mobile, Acrobat, and Acrobat Reader are also impacted, with specific versions listed. The advisory provides separate vendor bulletins for each product. CERT-In urges immediate patching of affected systems, emphasizing that internet-facing commerce deployments should be prioritized.
Remediation involves applying the vendor-provided updates, specifically apsb26-138 and apsb26-146 for Adobe Commerce, and the corresponding bulletins for the remaining products.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.