1.
CVE-2026-75650 (CVSS 10.0) lets unauthenticated attackers inject PHP through Magento's email template engine for RCE, with in-the-wild exploitation and Rust backdoors confirmed before the hotfix.
Skip to content
Curated 1 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-75650.