Executive brief
Adobe Commerce and Magento are e-commerce platforms used by thousands of online retailers to manage their storefronts and customer transactions. A vulnerability in the template engine allows attackers to inject and execute malicious code, potentially leading to complete compromise of the platform, theft of customer data, and unauthorized control of the online store. This flaw is currently being actively exploited by attackers.
Technical details
This vulnerability involves improper neutralization of special elements within a template engine used by Adobe Commerce and Magento Open Source. Template injection flaws occur when user-controlled input is not properly sanitized before being processed by the template engine, allowing attackers to inject malicious template syntax that gets evaluated as code. The vulnerability allows arbitrary code execution, which represents the highest severity of compromise. The fact that this vulnerability is being actively exploited in the wild indicates that attack methods are publicly known or easily discoverable. Patches or mitigations should be applied immediately to all affected instances.
Affected products
- Adobe Adobe Commerce
- Adobe Magento Open Source
Timeline
- 2026-09-08: disclosed
- 2026-09-08: exploited