Cookie Consent by Free Privacy Policy Generator

Adobe Confirms Active Exploitation of Commerce Platform Zero-Day Vulnerability

Adobe has patched over 170 vulnerabilities across its product range, including an actively exploited zero-day flaw in Adobe Commerce, according to SecurityWeek. The vulnerability, tracked as CVE-2026-75650, allows unauthenticated attackers to execute arbitrary code on affected systems. Adobe has confirmed that the flaw is being exploited in the wild, though the company has not disclosed details about the scope or nature of the attacks. The Commerce platform is widely used by retailers and e-commerce businesses to manage online storefronts, payment processing and customer data. Adobe has released patches and is urging customers to apply the updates immediately. The September update also includes fixes for critical vulnerabilities in Adobe Acrobat, Reader, Photoshop, Illustrator and other widely deployed applications.

Why this matters for UK organisations

For UK organisations running Adobe Commerce or other Adobe enterprise software, this represents an immediate patching priority. E-commerce platforms are high-value targets because they process payment card data, customer personal information and commercially sensitive transaction records. An unauthenticated remote code execution flaw in this context creates significant risk of data breach, payment fraud, reputational damage and regulatory consequences under UK GDPR. The fact that the vulnerability is already being exploited in the wild means that organisations should assume adversaries have working exploit code and are actively scanning for vulnerable instances. Beyond Adobe Commerce, the broader Adobe patch release includes critical fixes across products that are widely deployed in UK businesses, particularly in marketing, creative, legal and professional services sectors where Adobe software is standard. Organisations that have not yet patched should treat this as an urgent priority, particularly for internet-facing systems or those handling sensitive customer or payment data.

What to review

UK organisations using Adobe Commerce or other Adobe enterprise products should prioritise patching immediately, particularly for internet-facing systems. Review whether Adobe software is being actively monitored for security updates, whether patching responsibilities are clearly assigned, and whether there is a process in place to respond rapidly when vendors confirm active exploitation of critical vulnerabilities. Organisations should also review whether there is visibility into which Adobe products are deployed across the business, whether software asset inventories are accurate and up to date, and whether there are technical controls in place to detect exploitation attempts or unusual activity on e-commerce platforms. Consider whether incident response plans account for scenarios involving compromised e-commerce systems, payment data exposure or customer data breaches, and whether there is clarity on regulatory reporting obligations under UK GDPR and PCI DSS where applicable.

Source: SecurityWeek

News and blog posts
The National Cyber Security Centre has published new guidance addressing the...
Adobe has patched over 170 vulnerabilities across its product range, including...
US federal agencies, including CISA, have issued a joint advisory warning that...
Today's brief reflects two significant operational challenges for UK...