Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
3 clusters · 12 sources · 5 days · First seen · Last updated
Magento and Adobe Commerce zero-day vulnerability
Overview
A critical zero-day vulnerability, known as ‘StyleSmuggler’ (CVE-2026-75650), was identified affecting Magento Open Source and Adobe Commerce platforms. The flaw allows for unauthenticated remote code execution (RCE) by leveraging the GraphQL interface to inject malicious PHP code into system files. This code is triggered during the generation of ‘Payment Transaction Failed Reminder’ emails, allowing for exploitation without the recipient opening the message.
Following the discovery of active exploitation that began around September 4, Adobe released an urgent security hotfix (APSB26-146) on September 7. The vulnerability carries a maximum CVSS score of 10.0. Security experts have noted that while the patch addresses the vulnerability, it does not remediate systems that were already compromised. Adobe has advised merchants to apply the patch and rotate encryption keys and potentially exposed credentials to ensure full security.
Security researchers at Sansec reported that observed malicious payloads include a PHP web shell and a Rust-based Linux backdoor. Adobe confirmed the vulnerability is being exploited in the wild, specifically noting the deployment of a 1.9MB Rust-based implant. This implant is designed to evade detection by masquerading as legitimate system processes, such as ‘chronyd’, and uses a heartbeat pattern disguised as routine NTP traffic to bypass network monitoring.
On September 8, CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, establishing a federal remediation deadline of September 11. Affected versions include Magento Open Source 2.4.7, 2.4.8, and 2.4.9.
Entities
Adobe · Magento · Sansec · Adobe Commerce · Australian Signals Directorate
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 4 SOURCES] Adobe confirmed that CVE-2026-75650 is being actively exploited in the wild. cybernoz.com · www.atwix.com · www.blogspan.net · dev.to
- [● 4 SOURCES] Adobe released a security patch (VULN-39341) on September 7, 2026. cybernoz.com · www.atwix.com · www.blogspan.net · dev.to
- [● 3 SOURCES] The vulnerability allows for unauthenticated remote code execution. cybernoz.com · www.atwix.com · dev.to
- [● 3 SOURCES] Remediation requires both applying the patch and rotating encryption keys and credentials. www.atwix.com · www.blogspan.net · dev.to
- [● 2 SOURCES] The vulnerability CVE-2026-75650 has a CVSS score of 10.0. www.atwix.com · dev.to
- [○ 1 SOURCE] Sansec codenamed the vulnerability StyleSmuggler. dev.to
- [○ 1 SOURCE] Exploitation of the zero-day vulnerability was observed starting September 4, 2026. dev.to
- [○ 1 SOURCE] Observed payloads include a Rust-based Linux backdoor and a PHP web shell. dev.to
Timeline
-
about 24 hours ago
[TECHNOLOGY] 2 sourcesAdobe patches critical Magento vulnerability exploited in the wildAdobe is patching a critical unauthenticated remote code execution vulnerability (CVE-2026-75650) in Magento and Adobe Commerce that is currently being exploited in the wild by attackers.
-
3 days ago
[TECHNOLOGY] 6 sourcesAdobe Commerce and Magento face critical zero-day vulnerabilityAdobe has patched a critical CVE-2026-75650 zero-day vulnerability in Magento and Adobe Commerce that allows unauthenticated remote code execution. Active exploitation has been observed.
-
6 days ago
[TECHNOLOGY] 5 sourcesMagento and Adobe Commerce hit by StyleSmuggler zero-day exploitA zero-day vulnerability named ‘StyleSmuggler’ is allowing unauthenticated attackers to exploit Magento and Adobe Commerce stores, installing persistent Rust-based backdoors via GraphQL and email rendering.
Sources
blogspan.net · cybernoz.com · dev.to · esecurityplanet.com · etailment.de · forkast.news · immittelstand.de · it-boltwise.de · linuxsecurity.com · masseyservices.com · sempreupdate.com.br · thecyberexpress.com
This summary has been updated 2 times: see revision history