Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Act now! Aussie cyber agency warns of active exploitation of Adobe Commerce and Magento Open Source vulnerability

The ACSC has said there is a “substantial number of potentially vulnerable instances within the Australian economy”.

Thu, 10 Sep 2026
Act now! Aussie cyber agency warns of active exploitation of Adobe Commerce and Magento Open Source vulnerability

The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has issued a critical alert warning Australian organisations of active exploitation of a perfect-10 vulnerability in Adobe Commerce and Magento Open Source, a pair of popular e-commerce platforms.

“ASD’s ACSC is aware of a substantial number of potentially vulnerable instances within the Australian economy and encourage system owners to follow the mitigation advice from the vendor,” the agency said in an advisory published on the evening of 9 September.

“This alert is relevant to all Australian organisations that utilise Adobe Commerce and Magento Open Source.”

 
 

The vulnerability in question, CVE-2026-75650, was initially disclosed on 7 September by Adobe; however, by 9 September, the company was already aware of malicious activity targeting the flaw.

“This is an urgent update related to CVE-2026-75650,” the company said in an update to its initial advisory.

“Adobe is aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants.”

The vulnerability has been added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities Catalog.

According to its CVE record, the vulnerability is an improper neutralisation of special elements used in a template engine vulnerability that could lead to remote code execution.

A patch for the vulnerability was released on 7 September, and the ACSC is urging Australian organisations that use the platform to prioritise patching.

“If using an unpatched version, organisations should update their version that includes this patch as a priority,” the ACSC said.

“ASD’s ACSC is aware of reported active exploitation of this vulnerability, but has no information to indicate that a specific industry or sector is being targeted.”

The ACSC recommends the following mitigation measures:

  • Check networks and environments for vulnerable Adobe platform versions.
  • Review Adobe’s mitigation advice.
  • If managed by a third party, confirm systems are patched and monitored for suspicious activity.
  • Apply patches as soon as practicable. If unavailable:
    • Upgrade to a patched version; or
    • Restrict and monitor access for unusual activity, scheduled tasks and suspicious logs.
  • Report suspected exploitation to ASD’s ACSC.
Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: