CVE-2026-75650
- CVSS
- —
- EPSS
- —
- CISA KEV
- Added 2026-09-08, due 2026-09-11
- Exploitation
- No report
- Public exploits
- 5 repositories
- State
- Unknown
Coverage

Actively exploitedTenable Research
StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day(opens the publisher's site in a new tab)
A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways CVE-2026-75650 is a critical remote…
Actively exploitedCISA advisories & alerts
CISA Adds Four Known Exploited Vulnerabilities to Catalog(opens the publisher's site in a new tab)
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link…
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev