- Adobe patched CVE-2026-75650 (CVSS 10.0), a zero-day in Commerce and Magento Open Source exploited since September 4, 2026.
- The “StyleSmuggler” flaw enables unauthenticated remote code execution through PHP injection in Magento’s email template system.
- Attackers are deploying Rust-based backdoors and PHP web shells; one server was compromised within 50 minutes of the first exploit.
- Previdian recorded 12 exploitation attempts from China and Romania; Adobe urges immediate application of the VULN-39341 hotfix.
Adobe on Monday issued security patches for a maximum-severity vulnerability in Adobe Commerce and Magento Open Source that has been under active exploitation since September 4, 2026. Tracked as CVE-2026-75650 (CVSS 10.0) and codenamed StyleSmuggler by Sansec, the flaw allows unauthenticated remote code execution through PHP code injection in Magento’s template system.
The vulnerability abuses the platform’s email template mechanism to trigger code execution via a “Payment Transaction Failed Reminder” message, according to Adobe’s advisory. Affected versions include Adobe Commerce 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.6 through 2.4.9, all through the August 2026 release.
Adobe has released the VULN-39341 hotfix and urged merchants to apply it immediately and rotate their encryption keys. The company confirmed it is “aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants.”
Researchers at Disrex reported a Magento server was compromised 50 minutes after the first StyleSmuggler exploitation was logged on September 4 at 10:20 p.m. UTC. Threat actors are using the flaw to deploy a Rust-based Linux backdoor that connects to an external server, as well as a PHP dropper that installs a web shell for arbitrary code execution.
Telemetry data from Previdian recorded 12 exploitation attempts against its honeypots since September 7 from two IP addresses in China and Romania. Founder and CEO Ryan Dewhurst said those attempts have been unsuccessful.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
Previous Articles:
- Polish court detains fifth suspect in Zondacrypto fraud case
- Bitcoin-Gold Correlation Hits 6-Year High as Hedge Demand Rises
- Cronos confirms $9.2M slipped away before Tectonic exploit rollback
- Presearch Shut Down and Left Me With 60 Cents. Their Own Filings Show Why.
- Nvidia CEO touts GPUs as revenue-generating assets
