Adobe Commerce/Magento CVE-2026-75650: Unauthenticated RCE via GraphQL
CVE-2026-75650 in Adobe Commerce/Magento presents a serious unauthenticated RCE risk via GraphQL.
The CVE-2026-75650 vulnerability in Adobe Commerce and Magento allows unauthenticated remote code execution (RCE) through GraphQL. An attacker can exploit a styles parameter in a GraphQL request to inject PHP code into Magento-generated content, which is then executed server-side when the system sends a standard email. With a CVSS score of 10.0, this critical issue requires immediate attention from engineers.
This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work