ZeroHour
BleepingComputerpublished ()ingested Bill Toulas1

Adobe fixes critical Magento zero-day exploited to backdoor servers

criticalExploit / PoC exploited in the wildimportance 88CVE-2026-75650
AI summary · glm-5.3

Adobe emergency-patches actively exploited max-severity Magento/Adobe Commerce zero-day CVE-2026-75650 (StyleSmuggler), used since Sept 4 to backdoor servers.

Adobe released an emergency hotfix (VULN-39341) for CVE-2026-75650, a max-severity zero-day dubbed StyleSmuggler affecting Adobe Commerce 2.4.4-2.4.9, Adobe Commerce B2B 1.3.3-1.5.3, and Magento Open Source 2.4.6-2.4.9, enabling arbitrary code execution. Sansec reports the flaw has been exploited since at least September 4 to plant a backdoor whose C2 host is disguised as an NTP server, leaving traces like 'Payment Transaction Failed Reminder' emails. A second attacker with unrelated tooling is exploiting the flaw to deploy a 485-byte PHP web shell that collects server details, checks pub/media writability, and exfiltrates data to an oast.site subdomain. Adobe recommends immediate hotpatching plus rotation of all secrets including admin passwords, API keys, database credentials, and SSH keys.

  • CVE-2026-75650 (StyleSmuggler) is a max-severity RCE zero-day exploited in the wild since at least September 4.
  • Affects Adobe Commerce 2.4.4-2.4.9, Commerce B2B 1.3.3-1.5.3, Magento Open Source 2.4.6-2.4.9.
  • Exploitation plants backdoors with C2 disguised as NTP servers; a second actor drops a 485-byte PHP web shell.
  • Adobe urges immediate VULN-39341 hotfix installation and rotation of all credentials and secrets.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-75650
Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CVE-2026-75650)

Adobe Commerce and Magento (including Adobe Commerce B2B) contain an improper neutralization of special elements used in a template engine (CWE-1336), a template-injection flaw that permits arbitrary code execution in the context of the current user. The flaw is reachable over the network by unauthenticated attackers, requires no user interaction, and its changed scope (CVSS 3.1 S:C) means injected code executes beyond the vulnerable component, producing a maximum-severity (CVSS 10.0) remote code execution condition. A successful attacker gains arbitrary code execution on the storefront server; in the observed campaign, intruders installed a Rust backdoor and a PHP web shell (dubbed 'StyleSmuggler') on compromised servers. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is in scope, with internet-facing e-commerce deployments most exposed. Exploitation is confirmed in the wild: the bug was abused as a zero-day before patching and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08.

Do: Apply Adobe's released patches immediately per vendor instructions, prioritizing internet-facing Commerce/Magento storefronts, and ensure compliance with CISA BOD 26-04 timelines for KEV entries. Hunt for 'StyleSmuggler' indicators of compromise, including unexpected Rust backdoor binaries and PHP web shells on hosts, and review template/theme customizations for tampering. Exact fixed version numbers are not included in the available data, so consult Adobe's advisory for the correct patched release for your Commerce/Magento version line.

10.02% KEV PoC
  • Adobe Commerce
  • Adobe Commerce B2B
  • Adobe Magento (open-source)
massroughly 100,000-300,000 internet-facing storefronts

Indicators of compromiseAll →

TypeIndicatorContext
domainoast.sites writable, and exfiltrates the data through requests to an oast.site subdomain, which is typically seen in security tests that u
Full article436 words · extracted from bleepingcomputer.com · click to collapse

Adobe fixes critical Magento zero-day exploited to backdoor servers

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.

E-commerce security company Sansec discovered that the flaw has been leveraged in attacks since at least September 4 to plant a backdoor on vulnerable websites.

The backdoor disguised its command-and-control (C2) host as a regular Network Time Protocol (NTP) server. However, it still leaves distinct signs of activity on compromised hosts, such as "Payment Transaction Failed Reminder" emails.

In an update yesterday, Adobe pushed a security fix that addresses the StyleSmuggler vulnerability in Adobe Commerce and Magento.

“This update resolves a critical vulnerability that could result in arbitrary code execution. Adobe is aware of CVE-2026-75650 being exploited in the wild,” reads the security advisory.

Adobe notes that the flaw impacts the following versions of its e-commerce products:

  • Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
  • Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
  • Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch

The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.

After installing the hotfix, administrators should enable maintenance mode, suspend cron jobs, and rotate all secrets, including administrator passwords, GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH keys, and API keys.

After rotation, it is recommended to flush the cache, restore cron execution, and disable maintenance mode.

Adobe says the hotfix has only been tested against the August 2026 releases of the affected product branches, and while it may work with other releases, compatibility with them has not been confirmed.

In an update to its original report, Sansec says that a second attacker with unrelated tooling has been observed exploiting CVE-2026-75650 to deploy a 485-byte PHP web shell.

The malware collects basic server details, checks whether the pub/media location is writable, and exfiltrates the data through requests to an oast.site subdomain, which is typically seen in security tests that use the Interactsh open-source tool.

Because exploitation activity has increased, administrators are strongly advised to apply Adobe's hotfix or mitigations as soon as possible.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/