Australian online retailers running Adobe Commerce or Magento Open Source had no fix available for three days while the flaw in those platforms was being used to take over stores. The Australian Signals Directorate published a critical alert about it on 9 September, two days after Adobe shipped a hotfix.
The vulnerability is CVE-2026-75650. Adobe assigned it a CVSS base score of 10.0, the maximum, on a vector requiring no privileges, no user interaction and no local access. ASD's description is precise: it is an "Improper Neutralisation of Special Elements Used in a Template Engine vulnerability, leading to unauthenticated remote code execution", and "exploitation requires the /graphql endpoint to be exposed".
In plain terms, attacker-supplied input reaches the platform's template system without being cleaned, and the platform later executes it as code. An attacker who can reach the store's GraphQL endpoint over the internet can run commands on the server. Nothing needs to be clicked and nobody needs to be logged in.
For a shopper, the exposure is whatever the store held: order records, addresses, account details, and any payment credentials the store had stored or could reach through its own integrations. No Australian retailer has notified a breach connected to this flaw, and there is no OAIC entry for it. That is not the same as saying none occurred. The notifiable data breach scheme allows 30 days to assess a suspected eligible breach, and exploitation began six days ago.
ASD's language is worth reading carefully, because it has been reported more loosely than it was written. The agency says it "is aware of reported active exploitation" of the vulnerability. It says it "is aware of a substantial number of potentially vulnerable instances within the Australian economy". And it says it "has no information to indicate that a specific industry or sector is being targeted". Potentially vulnerable is exposure. It is not compromise, and ASD has not said an Australian organisation has been compromised.
No party has produced a count of exposed Australian stores. Not ASD, not Adobe, not any scanning outfit that has published a methodology. Any figure attached to this story at present has no named producer behind it.
Adobe published bulletin APSB26-146 on 7 September at its highest priority rating and confirmed that it "is aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants". The affected versions run to Adobe Commerce 2.4.9-2026-aug and earlier, Adobe Commerce B2B, and Magento Open Source 2.4.9-2026-aug and earlier, which covers essentially every supported release.
The fix is not a version upgrade. Adobe shipped hotfix VULN-39341 as a set of composer patch files keyed to release branch, so an operator has to identify their exact patch level and apply the matching file. Adobe has published nothing for the 2.2 and 2.3 branches or for 2.4.0 through 2.4.3, which are out of support.
Patching also does not finish the job. Adobe's own remediation guidance says operators must "rotate not only your encryption key but all credentials that may have been encrypted or exposed using it, including server, API, and integration credentials", and warns that "rotating the encryption key alone does not invalidate credentials that may already have been exposed". Its checklist covers admin passwords, REST, SOAP and GraphQL integration tokens, OAuth secrets, payment gateway credentials, database credentials and deploy keys, rotated at the source rather than only inside the platform.
The exposure window is the part operators will be dealing with for weeks. The Dutch security firm Sansec, which sells monitoring and blocking products for this platform and disclosed the flaw before a CVE or an Adobe advisory existed, dates the first confirmed compromise to 4 September. Adobe's hotfix landed on 7 September. Sansec's own warning is that patching "closes the hole but does not clean a store that was already hit", and that stores were exploited for three days before a fix existed. Sansec is the vendor of a product that addresses this, and its account of what it found on customer systems has not been confirmed by ASD or Adobe.
The United States added CVE-2026-75650 to CISA's Known Exploited Vulnerabilities catalogue on 8 September with a remediation deadline of 11 September, a three-day window for federal civilian agencies. The catalogue entry records ransomware campaign use as unknown.
Nobody has attributed the attacks. ASD names no threat actor and no foreign state, and neither does Adobe.
What is known: a maximum-severity flaw in widely deployed retail software, exploited before a patch existed, patched on 7 September, and rated critical by ASD on 9 September. What is not known: how many Australian stores were exposed, how many were compromised, and by whom. ASD is asking affected organisations to contact it on 1300 292 371, and says system owners should apply the patch as a priority.




