← Blog · · df00tech

CISA Adds Actively Exploited Adobe Commerce/Magento Template Engine Injection Flaw to KEV Catalog

breaking kev Adobe CVE-2026-75650

Adobe has disclosed a template-engine injection vulnerability in Adobe Commerce and Magento Open Source, tracked as CVE-2026-75650, described as an improper neutralization of special elements used in a template engine. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, indicating it is being actively exploited in the wild. No CVSS score has been published yet, and CISA has not indicated known ransomware campaign use of this vulnerability at this time.

Why It Matters

Template injection vulnerabilities in e-commerce platforms are historically high-value targets: Adobe Commerce and Magento have a long track record of being exploited for arbitrary code execution, leading to webshell deployment, payment card skimming (Magecart-style attacks), and full storefront compromise. Given CISA's KEV designation, organizations running affected Adobe Commerce or Magento Open Source deployments should treat this as an urgent, currently-exploited threat rather than a theoretical risk.

What Defenders Should Do Now

  • Consult Adobe's security bulletin (APSB26-146) immediately to confirm affected versions and apply the vendor-supplied patch or mitigation.
  • Inventory all internet-facing Adobe Commerce and Magento Open Source instances, including staging/dev environments that may be overlooked.
  • Review web server and application logs for anomalous requests involving template syntax or unexpected server-side rendering behavior around the disclosure date and in the preceding weeks.
  • Hunt for unexpected file writes, new admin users, or unfamiliar scheduled tasks/cron jobs on Magento/Commerce hosts, which are common post-exploitation indicators for this class of vulnerability.
  • Monitor outbound connections from Commerce/Magento servers for signs of webshell check-in or data exfiltration, and watch for unauthorized modifications to checkout/payment pages consistent with skimming activity.
  • If patching cannot occur immediately, consider WAF rules or virtual patching to filter template-injection-style payloads as an interim mitigation.

This is developing intelligence based on a same-day CISA KEV addition and Adobe's initial advisory; further technical details, a CVSS score, and exploitation specifics may emerge as the vulnerability is analyzed further. For the authoritative advisory, see Adobe's bulletin: APSB26-146.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.