Erforderlich für den Betrieb der Seite (Login, Einstellungen, Sicherheit). Immer aktiv.
Magento/Commerce-KEV-FAQ — Hotfix Applied ≠ behoben ohne Schlüsselrotation
FAQ-ENTWURF, kein PoC. Adobe APSB26-146 / CVE-2026-75650 CVSS 10.0; KEV-Frist 11.09. überfällig. Hotfix VULN-39341 Applied ≠ behoben ohne Key- und Credential-Rotation. Nur Soft-Auris-Posture.
FAQ: Warum reicht „hotfix Applied“ nach APSB26-146 nicht?
Adobe APSB26-146 betrifft CVE-2026-75650 (unsachgemäße Neutralisierung in der Commerce/Magento-Template-Engine → unauthentifizierte beliebige Codeausführung; CVSS 10.0 laut Adobe). CISA KEV nahm sie am 08.09.2026 auf, Frist 11.09.2026 — Restexposition als überfällige Residualsuche behandeln. Hotfix VULN-39341 Applied ist keine Remediation, bis Encryption Key und Payment-/Integration-/API-/SSH-Credentials (u. a.) beim Provider rotiert sind.
Quellen: Adobe APSB26-146 · Experience League commerce-apsb26-146 · CISA KEV.
FAQ — Beweist ein Versionsstring den Patch? Nein. Hotfix-Status VULN-39341 laut Adobe als Applied bestätigen; dem Versionsstring allein nicht vertrauen.
FAQ — Was muss nach dem Hotfix rotieren? Encryption Key und Admin-, Integrations-, OAuth-, Payment-, DB-, SSH- und Extension-Credentials an der Quelle — Adobe Experience-League-Rotationscheckliste paraphrasieren, dann erneut attestieren.
Soft-Auris-Posture (nur Analogie): Live-Check @ 2026-09-21T06:42:00.412Z mit gebundenem tenant_id, org_id null und kurzlebigem m2m, 0 Isolationsverletzungen — Produkt-Identitätsisolation, keine Magento-Zertifizierung und kein Sovereign-Cloud-Claim.
# Magento/Commerce MSP checklist — NO PoC
1. Confirm VULN-39341 hotfix Applied (do not trust version string alone)
2. Rotate encryption key per Adobe Experience League guidance
3. Rotate admin / integration / OAuth / payment / DB / SSH / extension credentials at source
4. Re-attest storefront health and payment integrations after rotation
5. Hunt residual compromise indicators on overdue KEV estates (due was 2026-09-11)
6. Soft Auris analogy only: tenant_id bound / org_id null / m2m = posture, not Magento cert
Verbot: kein Exploit/PoC. Keine ACN/C5/SecNumCloud/CLOUD-Act-Claims. Soft Auris = nur Posture-Evidenz.