Reporting that more than 3,800 online stores were compromised materially raises the response standard for an already exploited Adobe Commerce and Magento flaw: verify the hotfix, hunt every node and rotate credentials where compromise cannot be excluded.
What changed
CVE-2026-75650 was already known and patched, but the material development is reporting that compromise spread to more than 3,800 stores. Security leaders should separate hotfix status from compromise status, preserve evidence and rotate exposed secrets where forensic assurance is incomplete.
Public record through 2026-09-29. Source references count citations across published briefings, including repeated sources. Explore the record and its limits →
What We Publish / What We Sell
D
Free · Public
The Daily
Five evidence-backed selections for security leaders, every weekday.
Security.io 0–100 editorial scores. Exposure combines deployed footprint and internet reach; Urgency combines active exploitation and remediation time; Business Consequence combines compromise depth, data sensitivity and revenue impact. These are editorial scores, not externally reported measurements. Exposure: 95. Urgency: 97. Business Consequence: 92. Focus the chart and use the up and down arrow keys for detail. Source: Security.io editorial assessment informed by Adobe, Sansec and independent reporting.