StyleSmuggler (CVE-2026-75650): Actively exploited Adobe Commerce/Magento zero-day patched, added to CISA KEV, and analyzed by Akamai
Adobe's September 7 hotfix VULN-39341 (APSB26-146) addressed CVSS 10.0 unauthenticated RCE zero-day CVE-2026-75650, dubbed StyleSmuggler, exploited since September 4, 2026 to deploy a Rust backdoor and PHP web shells; CISA added it to the KEV catalog on…
CVE-2026-75650 is a maximum-severity (CVSS 10.0) unauthenticated remote code execution zero-day in Adobe Commerce and Magento, dubbed StyleSmuggler by Sansec, which injects PHP code via crafted style properties in Magento template processing and executes it when a Payment Transaction Failed Reminder email is rendered. Exploitation began September 4, 2026, three days before Adobe shipped emergency hotfix VULN-39341 (APSB26-146) on September 7. Per BleepingComputer and Tenable, affected versions are Adobe Commerce 2.4.4-2.4.9, Adobe Commerce B2B 1.3.3-1.5.3, and Magento Open Source 2.4.6-2.4.9, while The Hacker News reports Magento Open Source 2.4.4-2.4.9 (the sources disagree); Canada's Cyber Centre advisory AV26-888 says affected versions extend through the August 2026 patch levels, and CSO Online reports exploitation confirmed on 2.4.7-2.4.9 and on patched 2.4.6-p15. Sansec and Disrex confirmed multiple victim stores across at least two distinct campaigns, including on the same stores; one managed server was compromised 50 minutes after the first report. The primary implant is a Rust-based Linux backdoor supporting x86-64 and arm64, with C2 at 99.84.67.186 over UDP port 123 disguised as NTP traffic; it persists at ~/.local/share/.gvfsd/gvfsd-user masquerading as kworker, fc-cache, or chronyd, restored by a cron job every five minutes and later twice hourly. A second, unrelated operator drops a 485-byte PHP web shell in the product-image cache that collects server details, checks pub/media writability, and exfiltrates data to an oast.site subdomain. Previdian honeypots recorded 12 exploitation attempts from two unique IPs in China and Romania since September 7, all unsuccessful. Adobe urges immediate hotfix installation plus rotation of encryption keys and all secrets, including admin passwords, API keys, database credentials, and SSH keys. CISA added CVE-2026-75650 to its Known Exploited Vulnerabilities catalog on September 10 (it was not yet listed as of September 8 per Tenable), with a September 11, 2026 FCEB patch deadline under BOD 22-01. The zero-day was part of a broader Adobe patch day covering 170+ vulnerabilities, including Campaign Classic command injection CVE-2026-82004 and ColdFusion RCE flaws CVE-2026-48273 and CVE-2026-75746. Related ecosystem news: Akamai published technical analysis of StyleSmuggler on September 14; Sansec reported on September 9 that vendor Amasty patched dozens of Magento/Adobe Commerce extensions, including two…
- CVE-2026-75650 (StyleSmuggler) is a CVSS 10.0 unauthenticated RCE zero-day exploiting PHP injection via crafted template style properties, triggered when rendering the Payment Transaction Failed Reminder email.
- Active exploitation began September 4, 2026; Adobe released emergency hotfix VULN-39341 (APSB26-146) on September 7, 2026 (CSO Online cites the hotfix as VULN-393411, a discrepancy against the other reports).
- Affected versions per BleepingComputer/Tenable: Adobe Commerce 2.4.4-2.4.9, Adobe Commerce B2B 1.3.3-1.5.3, Magento Open Source 2.4.6-2.4.9; The Hacker News reports Magento Open Source 2.4.4-2.4.9 (sources disagree); CSO Online confirms…
- Rust-based Linux backdoor (x86-64 and arm64) uses C2 at 99.84.67.186 over UDP 123 disguised as NTP, persists at ~/.local/share/.gvfsd/gvfsd-user masquerading as kworker, fc-cache, or chronyd, restored by cron every five minutes (later…
- A second, unrelated operator deploys a 485-byte PHP web shell in the product-image cache that collects server details, checks pub/media writability, and exfiltrates to an oast.site subdomain; Sansec and Disrex confirmed at least two…
- One managed server was compromised 50 minutes after the first report; Previdian honeypots logged 12 exploitation attempts from two unique IPs (China and Romania) since September 7, all unsuccessful.
- CISA added CVE-2026-75650 to the KEV catalog on September 10, 2026; FCEB agencies face a September 11, 2026 patch deadline under BOD 22-01 (not in KEV as of September 8, per Tenable).
- Adobe recommends applying VULN-39341 and rotating encryption keys, admin passwords, API keys, database credentials, and SSH keys; defenders should hunt IoCs under pub/media.
Coverage timelineoldest first · each row is one article
- · 8d agoAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
The Hacker News· 92
Adobe patches actively exploited Magento zero-day CVE-2026-75650 (CVSS 10.0), abused since Sept 4 to deploy a Rust backdoor and PHP web shells.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-24086 | Unauthenticated RCE via checkout input-validation flaw in Adobe Commerce/Magento Adobe Commerce and Magento Open Source versions 2.4.3-p1 and earlier and 2.3.7-p2 and earlier contain an improper input validation flaw (CWE-20) in the checkout process. A remote attacker can trigger it with no privileges and no user interaction by submitting crafted input to a store's checkout flow, and successful exploitation results in arbitrary code execution on the server hosting the storefront. Any Adobe Commerce or Magento Open Source storefront running the affected versions is exposed, and because these are internet-facing e-commerce sites the practical exposure is broad. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15), its EPSS exploitation probability is 99.2% (100th percentile), and news reports describe ongoing attacks against Magento 2 stores, including recurring 'Xurum' attack campaigns and template-based attacks. Do: Upgrade every store to an Adobe-patched release per the vendor's instructions - i.e., any release newer than 2.4.3-p1 on the 2.4.x line or newer than 2.3.7-p2 on the 2.3.x line - noting that headlines indicate companion Magento CVEs were fixed in the same patch release, so consult Adobe's advisory for the full list. Because exploitation is unauthenticated and confirmed in the wild, prioritize internet-facing shops; WAF rules may reduce risk, but reports indicate WAF bypasses in related Magento attacks, so patching is the only reliable fix. After patching, review web server and application logs for exploitation attempts against the checkout flow and check affected hosts for indicators of compromise. | 9.8 | 99% | KEV |
| massroughly 100,000-300,000 online storefronts (Magento/Adobe Commerce is among the most widely deployed e-commerce platforms) | |
| CVE-2024-34102 | XXE vulnerability enabling RCE in Adobe Commerce and Magento Open Source CVE-2024-34102 is an improper restriction of XML external entity reference (XXE) vulnerability (CWE-611) in Adobe Commerce and Magento Open Source, where the platform does not properly restrict external entities when processing XML, so an attacker who can submit crafted XML containing external entity references can have it parsed with attacker-controlled resources. XXE flaws classically enable local file disclosure and server-side request forgery, and in this case Adobe states the flaw allows remote code execution on the affected server. Any organization running a vulnerable Adobe Commerce or Magento Open Source storefront is affected, and because these are internet-facing e-commerce platforms that routinely process XML input, exposure is likely to be broad. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-17, confirming exploitation in the wild, and its EPSS score of ~100% (100th percentile) indicates near-certain near-term exploitation activity; no public proof-of-concept is known and CVSS has not yet been scored. CISA lists ransomware use as unknown, so a ransomware connection should not be assumed. Do: Apply Adobe's security updates for Adobe Commerce and Magento Open Source per the vendor's June 2024 advisory (APSB24-40), or, per the CISA KEV required action, apply vendor-recommended mitigations or discontinue use of the product if patches are unavailable. Review any endpoints or integrations that accept XML from untrusted users and hunt for signs of XXE exploitation, such as unexpected outbound requests, anomalous file reads, or webshell artifacts. Continue monitoring Adobe and CISA KEV for updated mitigation guidance and remediation deadlines. | 9.8 | 100% | KEV PoC |
| mass≈150,000+ storefronts (public technology scans report on the order of 100k-250k live Magento-based sites) | |
| CVE-2025-54236 | Unauthenticated Session Takeover in Adobe Commerce and Magento (SessionReaper) Adobe Commerce and Magento Open Source contain an improper input validation flaw (CWE-20), widely tracked as 'SessionReaper', that lets a remote, unauthenticated attacker take over user sessions. The flaw is exploitable over the network with no privileges and no user interaction (CVSS 3.1 9.1, critical). A successful attacker hijacks legitimate customer or admin sessions, yielding high confidentiality and integrity impact; a public writeup additionally describes unauthenticated exploitation potentially reaching code execution. Anyone running Adobe Commerce (including Commerce B2B) or Magento Open Source on the affected 2.4.x releases is exposed. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2025-10-24, reporting headlines cite over 250 observed attacks, EPSS is 94.5%, and roughly 3 in 5 stores were reported as still unpatched. Do: Immediately upgrade every affected 2.4.x line to a release newer than 2.4.9-alpha2/2.4.8-p2/2.4.7-p7/2.4.6-p12/2.4.5-p14/2.4.4-p15 per Adobe's security advisory. Because the flaw is on CISA's KEV list, federal agencies must apply the vendor's mitigations (or BOD 22-01 cloud guidance) or discontinue use; other defenders should prioritize patching given 250+ observed attacks and 94.5% EPSS. Until patched, watch for indicators of session takeover — unexpected customer or admin sessions, unfamiliar admin accounts, and anomalous session activity — and review Adobe's advisory for interim mitigations. | 9.1 | 95% | KEV PoC |
| mass≈100,000+ internet-facing Adobe Commerce/Magento storefronts (order of magnitude 10^5) | |
| CVE-2026-48273 | Eval Injection RCE in Adobe ColdFusion (CVSS 9.9, low-privileged attacker) CVE-2026-48273 is a critical (CVSS 9.9) eval injection flaw (CWE-95) in Adobe ColdFusion in which untrusted input is not properly neutralized before it is placed into dynamically evaluated code. A remote attacker who has only low-privileged access to a vulnerable ColdFusion server can trigger the flaw over the network, with no user interaction required. Successful exploitation yields arbitrary code execution in the context of the current user, and the changed CVSS scope (S:C) indicates the impact can extend beyond the directly vulnerable component, a pattern typical of ColdFusion flaws that enable broader system-level code execution. All Adobe ColdFusion deployments are potentially affected; the source data does not specify affected version ranges, so admins should consult Adobe's bulletin for the exact versions fixed. As of this writing there is no known public proof-of-concept and the flaw is not in CISA KEV, though EPSS assigns a 1.7% probability of exploitation within 30 days; the fix shipped in Adobe's large recent patch batch, which also addressed three CVSS 10.0 ColdFusion and Campaign Classic flaws. Do: Apply the Adobe ColdFusion security update covering this CVE from the current patch batch immediately on all ColdFusion servers, prioritizing any that are internet-exposed, and confirm your exact version against Adobe's bulletin since fixed versions are not listed here. Because only low-privileged access is required and no user interaction is needed, audit which accounts and request paths feed untrusted input into dynamically evaluated expressions and restrict or validate such inputs. No public PoC or known exploitation exists yet, so monitor Adobe advisories and threat feeds for updated indicators of compromise. | 9.9 | 2% |
| large~tens of thousands of internet-exposed ColdFusion servers (estimate; Adobe does not publish install counts) | ||
| CVE-2026-71362 | Unauthenticated Privilege Escalation Flaw in Adobe Commerce (Magento) CVE-2026-71362 is an incorrect-authorization flaw (CWE-863) in Adobe Commerce, the e-commerce platform formerly known as Magento, in which authorization checks are applied incorrectly and can be bypassed. It is triggered over the network without authentication or user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). A successful attacker gains elevated access to sensitive resources — a privilege-escalation condition that Adobe's APSB26-92 advisory and press coverage describe as an account-takeover risk. Any organization running an unpatched Adobe Commerce/Magento deployment is affected; exact version ranges are listed in Adobe security bulletin APSB26-92. The flaw came under active attack shortly after public disclosure, and its EPSS score of 25.1% (98th percentile) signals a high likelihood of continued near-term exploitation. Do: Apply the fix released under Adobe advisory APSB26-92 immediately, prioritizing internet-facing Commerce/Magento instances, and check the bulletin for the exact patched version ranges for your deployment. Because exploitation requires no credentials or user interaction, review admin accounts, API integrations, and user/role assignments for unauthorized privilege changes, and restrict admin-panel and storefront API access where feasible. Monitor Adobe's advisory for indicators of compromise given confirmed in-the-wild exploitation. | 9.1 | 25% |
| mass≈200,000+ Magento/Adobe Commerce storefronts worldwide | ||
| CVE-2026-7565 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, 4.1.4 via the 'import-user-file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. NVD description · AI analysis pending | 4.9 | <1% |
| — | ||
| CVE-2026-75650 | Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CVE-2026-75650) Adobe Commerce and Magento (including Adobe Commerce B2B) contain an improper neutralization of special elements used in a template engine (CWE-1336), a template-injection flaw that permits arbitrary code execution in the context of the current user. The flaw is reachable over the network by unauthenticated attackers, requires no user interaction, and its changed scope (CVSS 3.1 S:C) means injected code executes beyond the vulnerable component, producing a maximum-severity (CVSS 10.0) remote code execution condition. A successful attacker gains arbitrary code execution on the storefront server; in the observed campaign, intruders installed a Rust backdoor and a PHP web shell (dubbed 'StyleSmuggler') on compromised servers. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is in scope, with internet-facing e-commerce deployments most exposed. Exploitation is confirmed in the wild: the bug was abused as a zero-day before patching and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08. Do: Apply Adobe's released patches immediately per vendor instructions, prioritizing internet-facing Commerce/Magento storefronts, and ensure compliance with CISA BOD 26-04 timelines for KEV entries. Hunt for 'StyleSmuggler' indicators of compromise, including unexpected Rust backdoor binaries and PHP web shells on hosts, and review template/theme customizations for tampering. Exact fixed version numbers are not included in the available data, so consult Adobe's advisory for the correct patched release for your Commerce/Magento version line. | 10.0 | 2% | KEV PoC |
| massroughly 100,000-300,000 internet-facing storefronts | |
| CVE-2026-75746 | SQL Injection Leading to Arbitrary Code Execution in Adobe ColdFusion CVE-2026-75746 is an SQL injection flaw (CWE-89) in Adobe ColdFusion that can escalate to arbitrary code execution in the context of the current user. A remote attacker who has already obtained high-privileged access, such as administrative-level credentials, can trigger the flaw over the network without any user interaction, and the changed scope means the impact extends beyond the vulnerable component's normal security boundary. Successful exploitation carries high-impact confidentiality, integrity, and availability consequences for the server. Organizations running Adobe ColdFusion, particularly internet-facing instances or deployments where privileged access is reachable by less-trusted users, are in scope. As of this analysis there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates roughly a 1.1% chance of exploitation within 30 days, indicating no known exploitation to date. Do: Apply the ColdFusion security update issued in Adobe's recent batch (which patched over 170 vulnerabilities) and confirm your installed build matches the fixed release listed in the Adobe advisory. Because the flaw requires high-privileged access, restrict administrative access to ColdFusion, rotate and harden privileged credentials, review logs for unexpected SQL activity from privileged accounts, and limit internet exposure of the server. No public PoC or KEV listing exists yet, but prioritize patching internet-facing ColdFusion instances given the critical base score. | 9.1 | 1% |
| largetens of thousands of internet-exposed ColdFusion servers (total installed base is larger but unreported) | ||
| CVE-2026-81963 +1 in the same advisory: …85880 | Local Privilege Escalation via Link Following in Windows Update Stack CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use. Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems. | 7.8 | <1% | KEV |
| masswell over 1,000,000 | |
| CVE-2026-82004 | Unauthenticated OS Command Injection in Adobe Campaign Classic Adobe Campaign Classic (ACC) contains an OS command injection flaw (CWE-78) in which special elements passed to an operating system command are improperly neutralized, allowing attacker-supplied commands to run on the host. Per the CVSS vector, it is reachable over the network (AV:N), requires no privileges or user interaction, and has changed scope (S:C), meaning a successful attack can also affect resources beyond the vulnerable component. An attacker gains arbitrary code execution in the context of the current user, with high impact to confidentiality, integrity, and availability. Any organization running an affected Adobe Campaign Classic deployment is potentially exposed, though only instances reachable over the network are practically exploitable. No public proof-of-concept or confirmed in-the-wild exploitation is known, EPSS estimates a ~1.4% probability of exploitation within 30 days, and the fix arrived in a large Adobe patch release covering 170+ vulnerabilities. Do: Upgrade Campaign Classic to the fixed build listed in Adobe's security bulletin for this CVE, since the affected and fixed version numbers are not included in the data provided. Until patched, limit network exposure of Campaign Classic application/web servers to trusted networks, as the flaw is exploitable without authentication or user interaction. Monitor for a public PoC or CISA KEV listing and review application service accounts for signs of unexpected command execution. | 10.0 | 1% |
| moderate~1,000-10,000 enterprise deployments worldwide (estimate; Adobe publishes no install counts) | ||
| CVE-2026-86218 | Pre-Auth Static Code Injection RCE in N-able N-central (Exploited in the Wild) CVE-2026-86218 is a static code injection flaw (CWE-96) in N-able's N-central on-premises remote monitoring and management (RMM) platform, carrying a maximum CVSS 4.0 score of 10.0. An unauthenticated, remote attacker triggers it by sending crafted network input to the N-central server that is improperly neutralized and persisted into application-managed code, which the server then executes — no privileges (PR:N) or user interaction (UI:N) are required. Successful exploitation yields full server compromise with high impact on confidentiality, integrity, and availability, and because N-central acts as the management hub for downstream customer endpoints, compromise can expose the entire managed estate. Any organization running an affected N-central release (before 2026.3.1.14) — primarily MSPs and corporate IT departments using N-able RMM — is affected. The flaw is confirmed exploited in the wild: N-able patched it as a zero-day, CISA added it to the KEV catalog on 2026-09-08, and it is the fourth N-central hotfix in five weeks, though no public PoC is known and ransomware use is unknown. Do: Upgrade N-central to 2026.3.1.14 or later (or apply N-able's hotfix) immediately, as the flaw is in CISA's KEV catalog and BOD 26-04 timelines apply to federal stakeholders. Until patched, remove direct internet exposure of the N-central server (restrict to VPN/management networks via firewall allowlists) since no authentication is needed for exploitation. Because in-the-wild exploitation is confirmed, review internet-facing N-central servers for indicators of compromise such as unexpected processes, unusual child processes of the web service, and new or suspicious accounts. | 10.0 | <1% | KEV PoC ×2 |
| large≈ tens of thousands of deployed/internet-exposed N-central servers (order of magnitude ~10k+), each managing many downstream customer endpoints |