started · updated
Adobe Commerce and Magento face critical zero-day vulnerability
Adobe has released an urgent security update to address a critical zero-day vulnerability, CVE-2026-75650, affecting Adobe Commerce and Magento Open Source platforms. The flaw, which has been assigned a maximum CVSS score of 10.0, allows for unauthenticated remote code execution.
Security researchers at Sansec, who have codenamed the exploit StyleSmuggler, reported that active exploitation began as early as September 4, 2026, several days before the official patch was released on September 7. Observed malicious payloads include a Rust-based Linux backdoor and a PHP web shell.
Adobe has issued an out-of-band hotfix (VULN-39341) to mitigate the risk. Experts emphasize that applying the patch alone is insufficient; merchants must also rotate all encryption keys and potentially exposed credentials to ensure complete remediation. The vulnerability is particularly dangerous because it can be triggered via a single request to an internet-facing storefront without requiring administrative credentials.
Entities
Adobe · Australian Signals Directorate · Magento · Sansec · ScaleCommerce
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 4 SOURCES] Adobe confirmed that CVE-2026-75650 is being actively exploited in the wild. cybernoz.com · www.atwix.com · www.blogspan.net · dev.to
- [● 2 SOURCES] The vulnerability CVE-2026-75650 has a CVSS score of 10.0. www.atwix.com · dev.to
- [○ 1 SOURCE] Observed payloads include a Rust-based Linux backdoor and a PHP web shell. dev.to
- [● 3 SOURCES] The vulnerability allows for unauthenticated remote code execution. cybernoz.com · www.atwix.com · dev.to
- [○ 1 SOURCE] Sansec codenamed the vulnerability StyleSmuggler. dev.to
- [● 4 SOURCES] Adobe released a security patch (VULN-39341) on September 7, 2026. cybernoz.com · www.atwix.com · www.blogspan.net · dev.to
- [○ 1 SOURCE] Exploitation of the zero-day vulnerability was observed starting September 4, 2026. dev.to
- [● 3 SOURCES] Remediation requires both applying the patch and rotating encryption keys and credentials. www.atwix.com · www.blogspan.net · dev.to