Adobe Commerce/Magento Open Source Arbitrary Code Execution (APSB26-146)

critical Nessus Plugin ID 344801

Synopsis

The Adobe Commerce/Magento Open Source instance installed on the remote host is missing a security hotfix.

Description

The version of Adobe Commerce/Magento Open Source installed on the remote host is affected by a vulnerability as referenced in the APSB26-146 advisory.

- Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. (CVE-2026-75650)

Adobe resolved this issue with the VULN-39341 hotfix rather than with a new release, so applying the fix does not change the version that Adobe Commerce / Magento Open Source reports. This plugin only reports a host when the fix is absent from the installation, so an affected version that already carries the hotfix is not flagged.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number and on the presence of the vendor hotfix in the installation.

Solution

Apply the VULN-39341 hotfix as referenced in the vendor advisory, then rotate the encryption key and every credential that may have been encrypted or exposed with it.

See Also

https://helpx.adobe.com/security/products/magento/apsb26-146.html

https://sansec.io/research/stylesmuggler-0day

http://www.nessus.org/u?78a58ae4

Plugin Details

Severity: Critical

ID: 344801

File Name: adobe_commerce_apsb26-146.nasl

Version: 1.1

Type: Local

Agent: unix

Family: Misc.

Published: 9/11/2026

Updated: 9/11/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.86

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-75650

CVSS v3

Risk Factor: Critical

Base Score: 10

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:adobe:commerce, cpe:/a:adobe:magento

Patch Publication Date: 9/7/2026

Vulnerability Publication Date: 9/5/2026

Reference Information

CVE: CVE-2026-75650