< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Adobe patches critical Magento vulnerability exploited in the wild

Adobe has released emergency patches for a critical unauthenticated remote code execution (RCE) vulnerability, identified as CVE-2026-75650, affecting Adobe Commerce and Magento Open Source. The flaw, dubbed ‘StyleSmuggler’, allows attackers to inject PHP code through the platform’s email template system. This code executes automatically when the application renders specific transaction reminders, requiring no user interaction or authentication.

Adobe confirmed that the vulnerability is being exploited in the wild. The exploit involves the deployment of a 1.9MB Rust-based implant designed to evade detection by masquerading as legitimate system processes, such as chronyd. To bypass network monitoring, the implant uses a specific heartbeat pattern disguised as routine NTP traffic.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 8, setting a federal remediation deadline of September 11. Affected versions include Magento Open Source 2.4.7, 2.4.8, and 2.4.9. Security experts advise Linux-based administrators to apply the hotfix and rotate all credentials, as attackers may have already harvested sensitive information.

Entities

Adobe · Adobe Commerce · CISA · Magento