Adobe published APSB26-146 on Labor Day afternoon and said, in one sentence of its own, that it is “aware of CVE-2026-75650 being exploited in the wild” — a CVSS 10.0 unauthenticated code-execution flaw reaching every supported branch of Adobe Commerce and Magento Open Source. That is the day’s top item, and the timing says more than the score does. Adobe’s regularly scheduled September release is set for September 8. It shipped out of band anyway, into a US federal holiday evening, with the NVD record landing after 5 p.m. Eastern. A vendor that gives up one day of coordination on a product this widely deployed is making a judgment about how bad this is, and that judgment is the more honest read.
The day had a thread, and it is not a record-quality problem. Today’s records are clear. What they lack is a version. Adobe’s “Updated Version” column contains the string “Hotfix for CVE-2026-75650” — prose where a build number belongs — so nothing that answers “are we patched?” by comparing a version to a range can confirm this fix. Red Hat published two 9.8s and was equally plain: the FreeIPA record lists no fixed package for any affected product, and the 389 Directory Server record lists 31 affected products, one unaffected, and zero fixed. Neither record is wrong. The remediation does not exist yet, and the vendor says so in the remediation field.
Those two Red Hat records are the second thing to deal with, and they are one attack chain rather than two bugs. FreeIPA’s description says the flaw is exploited “combined with a related flaw in the underlying directory server’s ACI evaluation (tracked separately)”; that companion, CVE-2026-76560, published an hour later and scored 7.5, is the load-bearing half of the 9.8. Red Hat says it independently confirmed the technique against a default, unmodified installation. What it offers in the meantime is a firewall rule for FreeIPA and, for the directory server, removing PLAIN from the SASL mechanisms the server will negotiate — the better of the two, because it addresses the mechanism instead of the reachability, though it asks administrators to introduce an explicit allow-list into deployments that, by Red Hat’s own account, mostly do not have one.
The inverse case is Advantech’s WISE-6610 gateway, where the fix shipped weeks ago in firmware 1.2.4_20260821 and no advisory was published for any of the three root command injections it closes — one of which has had a working public exploit since February. Below that the day turns to scoring and record quality rather than urgency: MediaTek labels three flaws High that its own CVSS v3.1 scores put at Medium, on a bulletin that states it grades by CVSS v3.1; h3’s cookie-loop hang is Moderate to the project and High to VulnCheck, and the whole 2.2-point gap is one availability metric, with the only fix a pre-release build; the Knowns batch closed five flaws in 0.30.0 and left a sixth described as reaching 0.33.0, the current release, with nowhere to upgrade to; and Bilibili Desktop turns off TLS certificate verification process-wide and names no fixed version either. Ardent Health’s 8-K is the one item that is not a vulnerability at all: the SEC made the company drop $97.7 million in non-GAAP add-backs, and the carve-out for its November 2023 ransomware attack survived untouched.
Still open. CVE-2026-75650 is not in CISA’s Known Exploited Vulnerabilities catalog as of this writing, so the one flaw confirmed under attack today carries no federal remediation deadline. Adobe’s next scheduled release is September 8, and APSB26-146 credits researchers against five CVE identifiers that do not appear in its own vulnerability table. The publication date of Sansec’s StyleSmuggler writeup — September 5 or September 7 — is unresolved. And Red Hat’s zero-fixed count now spans 31 products on one record and 41 on the other, eleven days after an earlier FreeIPA privilege-escalation flaw that still has none.
