VulnerabilityBleeping Computer
10.0 — CRITICAL
Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Adobe Commerce and Magento were exploited by attackers using a zero-day vulnerability dubbed StyleSmuggler, allowing them to plant backdoors on vulnerable websites, with attacks observed since September 4.
⚙️Technical Details
CVEs
CVE-2026-75650
Affected Systems
Adobe Commerce versions 2.4.4 through 2.4.9Adobe Commerce B2B versions 1.3.3 through 1.5.3Magento Open Source versions 2.4.6 through 2.4.9
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Administrators of vulnerable Adobe Commerce and Magento installations, including e-commerce websites.
🛡️Recommended Actions
1Enable maintenance mode
2Suspend cron jobs
3Rotate all secrets, including administrator passwords, GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH keys, and API keys
📦Affected Products
Adobe CommerceMagento
🔐NVD Verified DataVERIFIED
CVE-2026-75650 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-1336
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
