Local Melbourne technicians available

Careers•Remote support•Contact
All newsroom

Newsroom · Cyber Security

Adobe Commerce and Magento: urgent patch and security checks

ASD warns of active exploitation of CVE-2026-75650. Check affected storefronts, Adobe’s hotfix, credential rotation and provider confirmation.

Australian organisations running Adobe Commerce or Magento Open Source should ask their website provider to confirm their response to CVE-2026-75650. ASD’s ACSC issued its alert on 9 September 2026, following Adobe’s security update on 7 September. Both report active exploitation. The practical question is whether your particular storefront is affected and whether the required remediation has been completed.

Who needs to check their storefront?

This alert concerns the technology behind an online store. Adobe’s bulletin APSB26-146 lists affected versions of Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Ask the person or company responsible for your website to identify the installed product and exact release, then compare it with Adobe’s affected-version table and hotfix instructions.

The ACSC says exploitation requires the /graphql endpoint to be exposed. Your provider should assess that condition alongside the installed version. Being a Melbourne business or a healthcare organisation does not, by itself, establish exposure: the relevant question is whether you use the affected platform. The ACSC reports no information indicating that a particular industry is being targeted.

What the vulnerability means

The flaw can allow an attacker to run code on an affected installation without first signing in. Adobe rates it critical, with a CVSS score of 10.0, and assigns the update its highest remediation priority, Priority 1. This is an actively exploited vulnerability, rather than a theoretical issue.

The ACSC urges affected organisations to apply the patch promptly. When a patch is unavailable for the version in use, its advice is to move to a version with a patch or restrict and monitor access while following the vendor’s guidance.

Patching is only part of Adobe’s instructions

Adobe’s detailed remediation guidance calls for the appropriate hotfix, encryption-key rotation and rotation of credentials that may have been encrypted or exposed using that key. It explains that changing the encryption key alone does not invalidate credentials that may already have been exposed.

Ask your provider to check the complete vendor procedure, including connected-service credentials, rather than treating a patch installation as the whole job. Adobe’s instructions include maintenance steps and requirements for credentials held at third-party services.

For Adobe Commerce on Cloud, Adobe also supplies a hotfix-status check using its Quality Patches Tool. Ask for the result of that check where applicable; the cloud-specific verification procedure should not be assumed to apply unchanged to every hosting arrangement.

Practical next steps for the business owner

Request a short written response from your website provider covering the installed product and version, whether the advisory applies, the hotfix applied and how it was verified, and the status of the credential-rotation steps. These questions turn the official instructions into a record you can review without running technical commands yourself.

Also ask whether the provider is monitoring for suspicious activity. The ACSC identifies unusual system activity, unexpected scheduled tasks and suspicious logs as matters to investigate. If suspicious activity is detected, it advises notifying the ACSC; affected organisations or those seeking assistance can call 1300 CYBER1 (1300 292 371).

Talk to Podium IT

Need a clear next step?

Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.

Encrypted in transit Securely stored

This form uses server-side validation, bot protection and rate limiting. For urgent support, call us directly.

General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.