Critical Zero-Day in Adobe Commerce (APSB26-146): What Merchants Need to Do Right Now

Table of Contents

Adobe has confirmed that CVE-2026-75650 is being actively exploited in the wild. If your store is on an affected version, this is not a patch to schedule for the next sprint.

On September 7, 2026, Adobe released APSB26-146, a critical security update for an Adobe Commerce zero-day vulnerability tracked as CVE-2026-75650. Unlike most security bulletins, this one comes with a specific, serious warning: Adobe itself says the vulnerability has already been exploited against Adobe Commerce merchants before the fix was public.

That distinction matters. A routine security patch closes a door before anyone tries it. A zero-day patch closes a door attackers may have already walked through. This post covers what the vulnerability is, which versions are exposed, and the full remediation process Adobe is asking merchants to follow, which goes well beyond just applying a patch.

What Is APSB26-146?

CVE-2026-75650 is an unauthenticated remote code execution vulnerability, the most severe category a platform vulnerability can fall into. It means an attacker doesn’t need a login, an admin account, or any existing access to the store. They can potentially run their own code on the server directly. Adobe has confirmed active exploitation of this flaw against real Adobe Commerce installations, which is what pushed this from a routine Magento security update to an urgent, out-of-cycle bulletin.

Which Versions Are Affected

This vulnerability spans a wide range of currently supported releases:

  • Adobe Commerce — versions 2.4.4 through 2.4.9 (the August 2026 patch level and earlier).
  • Adobe Commerce B2B — versions 1.3.3 through 1.5.3 (the August 2026 patch level and earlier).
  • Magento Open Source — versions 2.4.6 through 2.4.9 (the August 2026 patch level and earlier).

If your store falls into any of these ranges and hasn’t applied the hotfix, this Adobe Commerce vulnerability applies to you right now, not hypothetically.

The Hotfix: VULN-39341

Adobe has published a Composer patch, VULN-39341, available directly from Adobe’s patch repository. It applies to Adobe Commerce on Cloud, Adobe Commerce on-premises, and Magento Open Source installations, and has been tested specifically against the August 2026 patch level of each affected version. After applying it, Commerce on Cloud merchants can verify the patch actually took using Adobe’s Quality Patches Tool, which reports the patch status directly rather than leaving you to guess.

Patching Is Not Enough — Rotate Everything

This is the part of the advisory most merchants will be tempted to skip, and it’s the part Adobe is most explicit about. Because this vulnerability allowed arbitrary code execution, an attacker who exploited it before the patch existed could have accessed your Magento credential rotation targets directly: your encryption key and everything that key protects. Rotating the encryption key alone does not invalidate credentials that were already exposed; each one needs to be rotated at its actual source.

Adobe’s remediation steps, in order, are:

  • Apply the VULN-39341 hotfix and enable maintenance mode before continuing.
  • Disable cron execution so scheduled jobs don’t run mid-rotation.
  • Rotate your encryption key, then every Admin panel user password.
  • Deactivate and regenerate all REST, SOAP, and GraphQL integration tokens.
  • Rotate OAuth client secrets for every connected third-party application.
  • Rotate payment gateway API credentials at the provider level — Stripe, Braintree, Adyen, PayPal, and any others in use.
  • Rotate database credentials, SSH and deploy keys, and any cron or system-privileged service account credentials.
  • Rotate API keys for shipping, tax, and other integrated extensions, then flush the cache, re-enable cron, and disable maintenance mode.

Why This Goes Beyond a Technical Fix

With active exploitation confirmed, this isn’t only a technical remediation checklist; it’s a potential incident. Depending on what an attacker accessed before the patch was available, this could touch payment processing compliance, breach notification obligations, and customer trust in ways a routine update never would. Treating this as “patch it when convenient” is the wrong read of Adobe’s own advisory language.

Signs Your Store May Already Be Affected

Because this vulnerability was exploited before Adobe’s fix existed, it’s worth checking for signs of prior compromise alongside applying the patch, rather than assuming a clean patch means a clean store:

  •  Unexpected admin users or accounts with escalated permissions you don’t recognize.
  • Unfamiliar integrations or API tokens under System > Extensions > Integrations that weren’t set up by your team.
  • Unusual cron jobs or scheduled tasks that don’t match your store’s normal automation.
  • Unexpected outbound traffic or server load reported by your hosting provider around the disclosure window.
  •  Changes to core files or templates that don’t correspond to a deployment your team made.

None of these alone confirm a compromise, but if you see any of them, treat the credential rotation as urgent rather than a precaution, and consider a deeper forensic review before calling the incident closed.

Frequently Asked Questions

Do I need to rotate credentials if I patch immediately?

If your store was running an affected version at any point before the patch was applied, yes. The patch stops the vulnerability from being exploited going forward; it doesn’t undo anything an attacker may have already accessed while the store was exposed.

How long does the full remediation process take?

For a store with a moderate number of integrations, the patch and credential rotation typically take a few hours of focused work, not a multi-day project, but rushing the credential rotation step to save time is exactly how a compromised token gets missed.

What if I’m not sure which Adobe Commerce version I’m running?

Your version is visible in the Admin panel footer or via the Magento CLI (`bin/magento –version`). If you’re unsure whether your specific version and patch level are affected, treat it as affected until confirmed otherwise; the cost of an unnecessary credential rotation is far lower than the cost of skipping a necessary one.

How Viha Digital Commerce Can Help

Applying a security-critical patch correctly, and then working through a full credential rotation without breaking checkout, payments, or third-party integrations, is exactly the kind of work that benefits from an experienced team rather than a rushed weekend fix. As a Magento development agency and Adobe Commerce development services partner, Viha Digital Commerce can help with:

  • Emergency hotfix deployment for stores still on an affected version.
  • Full credential rotation executed in the correct order, without disrupting live payment or integration flows.
  • A post-incident Magento security audit to check for signs of prior compromise, not just confirm the patch is applied.

If you’re unsure whether your store is on an affected version, or you want an experienced team to handle the patch and full credential rotation correctly the first time, reach out to Viha Digital Commerce today; this is not an advisory to sit on.

editor's pick

Get A Quick Quote

Your eCommerce Solution Specialist

    Get Expert Solutions

    Go to Top