< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

3 clusters · 12 sources · 5 days · First seen · Last updated

Magento and Adobe Commerce zero-day vulnerability

Overview

A critical zero-day vulnerability, known as ‘StyleSmuggler’ (CVE-2026-75650), was identified affecting Magento Open Source and Adobe Commerce platforms. The flaw allows for unauthenticated remote code execution (RCE) by leveraging the GraphQL interface to inject malicious PHP code into system files. This code is triggered during the generation of ‘Payment Transaction Failed Reminder’ emails, allowing for exploitation without the recipient opening the message.

Following the discovery of active exploitation that began around September 4, Adobe released an urgent security hotfix (APSB26-146) on September 7. The vulnerability carries a maximum CVSS score of 10.0. Security experts have noted that while the patch addresses the vulnerability, it does not remediate systems that were already compromised. Adobe has advised merchants to apply the patch and rotate encryption keys and potentially exposed credentials to ensure full security.

Security researchers at Sansec reported that observed malicious payloads include a PHP web shell and a Rust-based Linux backdoor. Adobe confirmed the vulnerability is being exploited in the wild, specifically noting the deployment of a 1.9MB Rust-based implant. This implant is designed to evade detection by masquerading as legitimate system processes, such as ‘chronyd’, and uses a heartbeat pattern disguised as routine NTP traffic to bypass network monitoring.

On September 8, CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, establishing a federal remediation deadline of September 11. Affected versions include Magento Open Source 2.4.7, 2.4.8, and 2.4.9.

Entities

Adobe · Magento · Sansec · Adobe Commerce · Australian Signals Directorate

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. about 24 hours ago

    [TECHNOLOGY] 2 sources
    Adobe patches critical Magento vulnerability exploited in the wild

    Adobe is patching a critical unauthenticated remote code execution vulnerability (CVE-2026-75650) in Magento and Adobe Commerce that is currently being exploited in the wild by attackers.

  2. 3 days ago

    [TECHNOLOGY] 6 sources
    Adobe Commerce and Magento face critical zero-day vulnerability

    Adobe has patched a critical CVE-2026-75650 zero-day vulnerability in Magento and Adobe Commerce that allows unauthenticated remote code execution. Active exploitation has been observed.

  3. 6 days ago

    [TECHNOLOGY] 5 sources
    Magento and Adobe Commerce hit by StyleSmuggler zero-day exploit

    A zero-day vulnerability named ‘StyleSmuggler’ is allowing unauthenticated attackers to exploit Magento and Adobe Commerce stores, installing persistent Rust-based backdoors via GraphQL and email rendering.

Sources

blogspan.net · cybernoz.com · dev.to · esecurityplanet.com · etailment.de · forkast.news · immittelstand.de · it-boltwise.de · linuxsecurity.com · masseyservices.com · sempreupdate.com.br · thecyberexpress.com

This summary has been updated 2 times: see revision history