External risk intelligence

Adobe Commerce Template Injection Arbitrary Code Execution

CVE advisoryKnown Exploit

CVE-2026-75650

Adobe Commerce is a web-based e-commerce platform designed to be publicly accessible over the internet to facilitate customer transactions and browsing, making its core functions internet-facing by design.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Adobe Commerce is susceptible to a critical vulnerability that could allow an unauthorized individual to execute arbitrary code, potentially impacting the integrity and availability of systems. This issue has a broad scope, meaning it could affect systems beyond the initial point of compromise.

  • Code execution flaw in Adobe Commerce.
  • Critical flaw impacts public-facing e-commerce.
  • Assess relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted input to an Adobe Commerce application exposed to the internet. This input would target a template engine feature, allowing the attacker to execute arbitrary code within the application's environment. Because this attack does not require user interaction and changes the scope of impact, it could lead to significant compromise.

  • Publicly accessible web interface.
  • Specially crafted input to template engine.
  • Arbitrary code execution with elevated privileges.

Live Threat

Current exploitation, exposure, and threat context

This Improper Neutralization of Special Elements vulnerability in Adobe Commerce could allow an unauthenticated attacker to execute arbitrary code on the affected system. This could occur when the system processes specially crafted input, potentially leading to unauthorized actions or data compromise in the context of the current user.

  • Arbitrary code execution in user context.
  • Unauthenticated remote input processing.
  • System compromise and data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

Adobe Commerce administrators, platform teams, and security teams should collaborate to address this critical vulnerability. The initial step involves identifying all instances of Adobe Commerce, assessing their exposure and business criticality, and then confirming the accountable owner for each instance to prioritize and plan remediation efforts.

  • Ownership likely resides with e-commerce platform administrators.
  • Verify external reachability and business criticality.
  • Plan remediation based on risk and vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Commerce?

Adobe Commerce is a comprehensive e-commerce platform used by businesses to build and manage online stores. It acts as a digital storefront, handling product catalogs, customer transactions, and inventory management. Because it is designed to interact directly with web shoppers, the software includes complex features like template engines that dynamically generate the pages users see in their browsers.

How does this template engine vulnerability work?

This flaw is classified as Improper Neutralization of Special Elements (CWE-1336). In simple terms, the software fails to properly filter instructions within its template processing logic. When an attacker sends specially crafted input, the system mistakes that input for legitimate commands, allowing the attacker to execute arbitrary code instead of just displaying text.

Do I need to interact with the site for this to trigger?

No, this vulnerability does not require any user interaction to be triggered. An attacker can initiate the exploit remotely by sending malicious input directly to the application. If the input reaches the vulnerable template engine feature, the system will process it automatically. Internal traffic that never reaches the application's input processing functions would not trigger this specific issue.

Why is this considered an external risk?

According to Halo Surface Signal, Adobe Commerce is fundamentally designed to be internet-facing to support customer browsing and purchasing. Because the platform must be reachable from the public web to function, any weakness in its input processing becomes an external attack surface that does not require the attacker to be inside your private corporate network.

What should I do if I run Adobe Commerce?

Start by identifying all instances of Adobe Commerce within your environment to determine which are reachable from the internet. Coordinate with your platform and security teams to verify the specific versions in use. Prioritize these assets based on their business criticality and wait for official updates or instructions from Adobe to remediate the vulnerability.

References