Feed›Vulnerability›Adobe fixes critical Magento zero-day exploited to backdoor ...
VulnerabilityBleeping Computer
10.0 — CRITICAL

Adobe fixes critical Magento zero-day exploited to backdoor servers

📅 8 September 2026 at 13:34 UTC📰 Bleeping ComputerView original source ↗
Adobe fixes critical Magento zero-day exploited to backdoor servers

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Adobe Commerce and Magento were exploited by attackers using a zero-day vulnerability dubbed StyleSmuggler, allowing them to plant backdoors on vulnerable websites, with attacks observed since September 4.

⚙️Technical Details
CVEs
CVE-2026-75650
Affected Systems
Adobe Commerce versions 2.4.4 through 2.4.9Adobe Commerce B2B versions 1.3.3 through 1.5.3Magento Open Source versions 2.4.6 through 2.4.9
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Administrators of vulnerable Adobe Commerce and Magento installations, including e-commerce websites.
🛡️Recommended Actions
1Enable maintenance mode
2Suspend cron jobs
3Rotate all secrets, including administrator passwords, GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH keys, and API keys
📦Affected Products
Adobe CommerceMagento
🔐NVD Verified DataVERIFIED
CVE-2026-75650 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-1336

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed