BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Adobe Patches Critical Magento Flaw Under Active Attack

Adobe patches critical zero-day in Commerce and Magento exploited since Sept 4, urges immediate fix.

  • Adobe patched CVE-2026-75650 (CVSS 10.0), a zero-day in Commerce and Magento Open Source exploited since September 4, 2026.
  • The “StyleSmuggler” flaw enables unauthenticated remote code execution through PHP injection in Magento’s email template system.
  • Attackers are deploying Rust-based backdoors and PHP web shells; one server was compromised within 50 minutes of the first exploit.
  • Previdian recorded 12 exploitation attempts from China and Romania; Adobe urges immediate application of the VULN-39341 hotfix.

Adobe on Monday issued security patches for a maximum-severity vulnerability in Adobe Commerce and Magento Open Source that has been under active exploitation since September 4, 2026. Tracked as CVE-2026-75650 (CVSS 10.0) and codenamed StyleSmuggler by Sansec, the flaw allows unauthenticated remote code execution through PHP code injection in Magento’s template system.

- Advertisement -

The vulnerability abuses the platform’s email template mechanism to trigger code execution via a “Payment Transaction Failed Reminder” message, according to Adobe’s advisory. Affected versions include Adobe Commerce 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.6 through 2.4.9, all through the August 2026 release.

Adobe has released the VULN-39341 hotfix and urged merchants to apply it immediately and rotate their encryption keys. The company confirmed it is “aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants.”

Researchers at Disrex reported a Magento server was compromised 50 minutes after the first StyleSmuggler exploitation was logged on September 4 at 10:20 p.m. UTC. Threat actors are using the flaw to deploy a Rust-based Linux backdoor that connects to an external server, as well as a PHP dropper that installs a web shell for arbitrary code execution.

Telemetry data from Previdian recorded 12 exploitation attempts against its honeypots since September 7 from two IP addresses in China and Romania. Founder and CEO Ryan Dewhurst said those attempts have been unsuccessful.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

MCP Python SDK OAuth flaw lets attackers steal credentials

High-severity OAuth credential theft flaw found in MCP Python SDK versions 1.9.1–1.29.1 and 2.0.0–2.1.1.Attacker-controlled...

Can BNB Coin Reclaim $1000 After 45% Slump?

BNB hit an all-time high of $1,369.99 in October 2025 but has since declined...

BTIG Boosts Robinhood Target to $135 on Solid Q3 Metrics

BTIG raised Robinhood's price target to $135 from $125, maintaining a Buy rating with...

Blockchain.com eyes $500M IPO as crypto capital markets thaw

Blockchain.com is reportedly targeting a $500 million initial public offering in 2026, seeking a...

AI agent hack: Australian Senate summons Altman, Amodei

Senator Sarah Hanson-Young invited OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei to...

Must Read

8 Best Bitcoin Offshore Hosting Providers

In this blog post, we'll list the top 8 best bitcoin offshore hosting providers that accept Bitcoin and other cryptocurrencies.As Bitcoin continues to grow...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading