< Back to all clusters
[TECHNOLOGY] · Germany · 6 sources

started · updated

Adobe Commerce and Magento face critical zero-day vulnerability

Adobe has released an urgent security update to address a critical zero-day vulnerability, CVE-2026-75650, affecting Adobe Commerce and Magento Open Source platforms. The flaw, which has been assigned a maximum CVSS score of 10.0, allows for unauthenticated remote code execution.

Security researchers at Sansec, who have codenamed the exploit StyleSmuggler, reported that active exploitation began as early as September 4, 2026, several days before the official patch was released on September 7. Observed malicious payloads include a Rust-based Linux backdoor and a PHP web shell.

Adobe has issued an out-of-band hotfix (VULN-39341) to mitigate the risk. Experts emphasize that applying the patch alone is insufficient; merchants must also rotate all encryption keys and potentially exposed credentials to ensure complete remediation. The vulnerability is particularly dangerous because it can be triggered via a single request to an internet-facing storefront without requiring administrative credentials.

Entities

Adobe · Australian Signals Directorate · Magento · Sansec · ScaleCommerce

Claims

What the coverage asserts, and how many sources carry each claim.