BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Adobe Patches Critical Magento Flaw Under Active Attack

  • Adobe patched CVE-2026-75650 (CVSS 10.0), a zero-day in Commerce and Magento Open Source exploited since September 4, 2026.
  • The “StyleSmuggler” flaw enables unauthenticated remote code execution through PHP injection in Magento’s email template system.
  • Attackers are deploying Rust-based backdoors and PHP web shells; one server was compromised within 50 minutes of the first exploit.
  • Previdian recorded 12 exploitation attempts from China and Romania; Adobe urges immediate application of the VULN-39341 hotfix.

Adobe on Monday issued security patches for a maximum-severity vulnerability in Adobe Commerce and Magento Open Source that has been under active exploitation since September 4, 2026. Tracked as CVE-2026-75650 (CVSS 10.0) and codenamed StyleSmuggler by Sansec, the flaw allows unauthenticated remote code execution through PHP code injection in Magento’s template system.

- Advertisement -

The vulnerability abuses the platform’s email template mechanism to trigger code execution via a “Payment Transaction Failed Reminder” message, according to Adobe’s advisory. Affected versions include Adobe Commerce 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.6 through 2.4.9, all through the August 2026 release.

Adobe has released the VULN-39341 hotfix and urged merchants to apply it immediately and rotate their encryption keys. The company confirmed it is “aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants.”

Researchers at Disrex reported a Magento server was compromised 50 minutes after the first StyleSmuggler exploitation was logged on September 4 at 10:20 p.m. UTC. Threat actors are using the flaw to deploy a Rust-based Linux backdoor that connects to an external server, as well as a PHP dropper that installs a web shell for arbitrary code execution.

Telemetry data from Previdian recorded 12 exploitation attempts against its honeypots since September 7 from two IP addresses in China and Romania. Founder and CEO Ryan Dewhurst said those attempts have been unsuccessful.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Polish court detains fifth suspect in Zondacrypto fraud case

A Polish court approved pretrial detention for Roman Ż., charged with computer fraud and...

Bitcoin-Gold Correlation Hits 6-Year High as Hedge Demand Rises

Bitcoin's correlation with Gold hits a six-year high, signaling its use as a hedge...

Cronos confirms $9.2M slipped away before Tectonic exploit rollback

Cronos confirmed $9.19 million left its blockchain before a network rollback reversed a crypto...

Presearch Shut Down and Left Me With 60 Cents. Their Own Filings Show Why.

I bought €100 of PRE about two and a half years ago. I was...

Nvidia CEO touts GPUs as revenue-generating assets

NVIDIA CEO Jensen Huang says the company's GPUs are a “productive, revenue-generating asset” as...

Must Read

What Are Anonymous Debit Cards And How Do They Work?

You've heard about anonymous debit cards, but what are they really? Anonymous Debit Cards are cards that let you make purchases without revealing your...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading