Apply This Magento Hotfix Today: APSB26-146 Is Already Being Exploited
Some Adobe bulletins you schedule. This one you stop the meeting for.
On 7 September 2026 Adobe released APSB26-146. Priority 1. One CVE: CVE-2026-75650. CVSS 10.0. No login required. A template-engine flaw that can run code on the server. And Adobe said it is already being exploited.
That combination does not show up often. When it does, scanners are already looking for stores that have not moved.
The short version
- This is a hotfix, not a new 2.4.x-2026-sep version. Apply Adobe’s fix for CVE-2026-75650.
- Unauthenticated + score 10 + active exploitation. There is no responsible reason to wait for a quieter window.
- The next day’s bulletin (APSB26-138) is a different patch. You need both.
Who is in the blast radius
Adobe Commerce 2.4.4 through 2.4.9 at the August level or earlier. Magento Open Source 2.4.6 through 2.4.9. The matching B2B packages. If August is not on yet, you are still in the affected set. Put the hotfix on the supported line you are running, then catch up the monthlies.
What “template engine”?
Magento renders a lot of storefront and email content through templates. If special characters in that pipeline are not neutralised, someone on the internet can sneak instructions the engine will execute. You do not need an admin password for this one. That is why the score is 10, and why Adobe did not wait for the regular Tuesday package.
The official write-up is APSB26-146. It is short on purpose. Read it, then apply the hotfix. Do not wait for a longer explainer.
What to do today
- Take a backup. Yes, even when you are in a hurry. A five-minute snapshot beats a restored “we will figure it out later” story.
- Put the hotfix on staging if you can do it the same day. If staging will take three days, say that out loud to whoever owns risk. Sitting unpatched while we “do it properly” is how these become incidents.
- Apply Adobe’s hotfix for CVE-2026-75650. Follow their install note, not a blog comment from 2024.
- Flush cache. Hit homepage, category, product, checkout, and any page that is heavy on custom templates.
- Then put APSB26-138 on this week’s calendar. Do not confuse the two.
Questions we keep getting
Is the September 2026-sep package enough on its own?
No. Adobe released this as a separate hotfix the day before the monthly. Their September bulletin says to apply the CVE-2026-75650 hotfix in addition to APSB26-138. Treat them as two tickets.
Can we wait until after a campaign weekend?
Not for this one. Active exploitation plus no login is the rare case where “we will do it Monday” is the riskier sentence. If you need us on a call tonight, say so.
Will the hotfix break the theme?
It can touch template handling, so yes, test the pages you actually sell from. In our experience the bigger risk is not applying it. Smoke-test, then ship.
Need the hotfix on production today?
Send the version string and access to staging if you have it. We will apply CVE-2026-75650, smoke-test the storefront, and tell you what is left for the September monthly.
