ZeroHour
Story · 1 source · 1 articlefirst updated ()

Adobe Patches 170+ Flaws as Commerce Zero-Day 'StyleSmuggler' (CVE-2026-75650) Is Exploited; Amasty Fixes Critical Magento Extension Bugs

What's new: First merged summary for this story. New this cycle: (1) SecurityWeek (Sept 8) reported Adobe's 170+ vulnerability patch release and identified Commerce/Magento zero-day CVE-2026-75650 (CVSS 10) as actively exploited since Sept 4 under the name StyleSmuggler, plus Campaign Classic and ColdFusion fixes; (2) Sansec (Sept 9) reported Amasty's patching of dozens of Magento extensions including two…
Merged summary · glm-5.3 · rewritten as coverage arrives

Adobe's bulk update covers 170+ vulnerabilities, headlined by actively exploited Adobe Commerce/Magento zero-day CVE-2026-75650 (CVSS 10, unauthenticated RCE, dubbed StyleSmuggler); Canada's Cyber Centre separately flags CVE-2026-71362 as exploited in the…

Adobe released fixes for more than 170 vulnerabilities across Experience Manager (107 flaws), Acrobat Reader (32), Photoshop (8), Illustrator, Animate and other products. The most severe is CVE-2026-75650, a CVSS 10 zero-day in Adobe Commerce/Magento enabling unauthenticated code injection and remote code execution. Attacks, dubbed StyleSmuggler, began September 4, with the injected code triggered via Magento's Payment Transaction Failed Reminder email; Sansec reported multiple threat actors deploying backdoors and web shells and urged rotating encryption keys and all source credentials. Akamai Security Research subsequently published its own analysis of StyleSmuggler. Adobe also patched critical Campaign Classic command injection (CVE-2026-82004) and two critical ColdFusion RCE flaws (CVE-2026-48273, CVE-2026-75746). Separately, the Canadian Centre for Cyber Security's advisory AV26-808 Update 1 states that open-source reporting indicates CVE-2026-71362 in Adobe Commerce is being exploited in the wild; the reports do not clarify whether this is the same or a distinct issue from CVE-2026-75650, and Commerce fixes are tracked in Adobe bulletin APSB26-92. In parallel, extension vendor Amasty patched dozens of Magento/Adobe Commerce modules, including two critical unauthenticated file upload flaws in Advanced Product Reviews and Gift Card that permit web shell upload and full store takeover via arbitrary upload locations that defeat standard PHP execution blocking under pub/media. A related Amasty Order Attributes flaw had previously seen Sansec Shield block over 12,000 exploitation attempts against 25% of Magento stores within three days.

  • CVE-2026-75650 is a CVSS 10 zero-day in Adobe Commerce/Magento allowing unauthenticated code injection leading to remote code execution; it has been exploited in the wild since September 4, 2026.
  • The campaign is dubbed StyleSmuggler; injected code is triggered through Magento's Payment Transaction Failed Reminder email, and multiple threat actors deployed backdoors and web shells, per Sansec.
  • Akamai Security Research published an analysis of CVE-2026-75650/StyleSmuggler on its security blog on September 14, 2026.
  • Canadian Cyber Centre advisory AV26-808 Update 1 (September 10, 2026) states CVE-2026-71362 in Adobe Commerce is being exploited in the wild per open-source reporting; sources cite two different exploited CVE IDs without clarifying whether…
  • Adobe's patch wave covers 170+ vulnerabilities: Experience Manager (107), Acrobat Reader (32), Photoshop (8), Illustrator, Animate, Campaign Classic, ColdFusion 2023/2025, Lightroom Classic, and Content Credentials SDKs.
  • Other critical fixes include Campaign Classic command injection CVE-2026-82004 and ColdFusion RCE flaws CVE-2026-48273 and CVE-2026-75746.
  • Adobe Commerce/Magento updates are tracked under Adobe security bulletin APSB26-92.
  • Sansec recommends rotating encryption keys and all source credentials for affected Commerce/Magento deployments.

Coverage timeline

  1. · 7d ago
    SecurityWeek· 88
    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    Adobe patched over 170 flaws, including in-the-wild zero-day CVE-2026-75650 (CVSS 10) in Adobe Commerce/Magento enabling unauthenticated RCE and web shell deployments.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-48273
Eval Injection RCE in Adobe ColdFusion (CVSS 9.9, low-privileged attacker)

CVE-2026-48273 is a critical (CVSS 9.9) eval injection flaw (CWE-95) in Adobe ColdFusion in which untrusted input is not properly neutralized before it is placed into dynamically evaluated code. A remote attacker who has only low-privileged access to a vulnerable ColdFusion server can trigger the flaw over the network, with no user interaction required. Successful exploitation yields arbitrary code execution in the context of the current user, and the changed CVSS scope (S:C) indicates the impact can extend beyond the directly vulnerable component, a pattern typical of ColdFusion flaws that enable broader system-level code execution. All Adobe ColdFusion deployments are potentially affected; the source data does not specify affected version ranges, so admins should consult Adobe's bulletin for the exact versions fixed. As of this writing there is no known public proof-of-concept and the flaw is not in CISA KEV, though EPSS assigns a 1.7% probability of exploitation within 30 days; the fix shipped in Adobe's large recent patch batch, which also addressed three CVSS 10.0 ColdFusion and Campaign Classic flaws.

Do: Apply the Adobe ColdFusion security update covering this CVE from the current patch batch immediately on all ColdFusion servers, prioritizing any that are internet-exposed, and confirm your exact version against Adobe's bulletin since fixed versions are not listed here. Because only low-privileged access is required and no user interaction is needed, audit which accounts and request paths feed untrusted input into dynamically evaluated expressions and restrict or validate such inputs. No public PoC or known exploitation exists yet, so monitor Adobe advisories and threat feeds for updated indicators of compromise.

9.92%
  • Adobe ColdFusion
large~tens of thousands of internet-exposed ColdFusion servers (estimate; Adobe does not publish install counts)
CVE-2026-71362
Unauthenticated Privilege Escalation Flaw in Adobe Commerce (Magento)

CVE-2026-71362 is an incorrect-authorization flaw (CWE-863) in Adobe Commerce, the e-commerce platform formerly known as Magento, in which authorization checks are applied incorrectly and can be bypassed. It is triggered over the network without authentication or user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). A successful attacker gains elevated access to sensitive resources — a privilege-escalation condition that Adobe's APSB26-92 advisory and press coverage describe as an account-takeover risk. Any organization running an unpatched Adobe Commerce/Magento deployment is affected; exact version ranges are listed in Adobe security bulletin APSB26-92. The flaw came under active attack shortly after public disclosure, and its EPSS score of 25.1% (98th percentile) signals a high likelihood of continued near-term exploitation.

Do: Apply the fix released under Adobe advisory APSB26-92 immediately, prioritizing internet-facing Commerce/Magento instances, and check the bulletin for the exact patched version ranges for your deployment. Because exploitation requires no credentials or user interaction, review admin accounts, API integrations, and user/role assignments for unauthorized privilege changes, and restrict admin-panel and storefront API access where feasible. Monitor Adobe's advisory for indicators of compromise given confirmed in-the-wild exploitation.

9.125%
  • Adobe Commerce (Magento)
mass≈200,000+ Magento/Adobe Commerce storefronts worldwide
CVE-2026-75650
Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CVE-2026-75650)

Adobe Commerce and Magento (including Adobe Commerce B2B) contain an improper neutralization of special elements used in a template engine (CWE-1336), a template-injection flaw that permits arbitrary code execution in the context of the current user. The flaw is reachable over the network by unauthenticated attackers, requires no user interaction, and its changed scope (CVSS 3.1 S:C) means injected code executes beyond the vulnerable component, producing a maximum-severity (CVSS 10.0) remote code execution condition. A successful attacker gains arbitrary code execution on the storefront server; in the observed campaign, intruders installed a Rust backdoor and a PHP web shell (dubbed 'StyleSmuggler') on compromised servers. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is in scope, with internet-facing e-commerce deployments most exposed. Exploitation is confirmed in the wild: the bug was abused as a zero-day before patching and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08.

Do: Apply Adobe's released patches immediately per vendor instructions, prioritizing internet-facing Commerce/Magento storefronts, and ensure compliance with CISA BOD 26-04 timelines for KEV entries. Hunt for 'StyleSmuggler' indicators of compromise, including unexpected Rust backdoor binaries and PHP web shells on hosts, and review template/theme customizations for tampering. Exact fixed version numbers are not included in the available data, so consult Adobe's advisory for the correct patched release for your Commerce/Magento version line.

10.02% KEV PoC
  • Adobe Commerce
  • Adobe Commerce B2B
  • Adobe Magento (open-source)
massroughly 100,000-300,000 internet-facing storefronts
CVE-2026-75746
SQL Injection Leading to Arbitrary Code Execution in Adobe ColdFusion

CVE-2026-75746 is an SQL injection flaw (CWE-89) in Adobe ColdFusion that can escalate to arbitrary code execution in the context of the current user. A remote attacker who has already obtained high-privileged access, such as administrative-level credentials, can trigger the flaw over the network without any user interaction, and the changed scope means the impact extends beyond the vulnerable component's normal security boundary. Successful exploitation carries high-impact confidentiality, integrity, and availability consequences for the server. Organizations running Adobe ColdFusion, particularly internet-facing instances or deployments where privileged access is reachable by less-trusted users, are in scope. As of this analysis there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates roughly a 1.1% chance of exploitation within 30 days, indicating no known exploitation to date.

Do: Apply the ColdFusion security update issued in Adobe's recent batch (which patched over 170 vulnerabilities) and confirm your installed build matches the fixed release listed in the Adobe advisory. Because the flaw requires high-privileged access, restrict administrative access to ColdFusion, rotate and harden privileged credentials, review logs for unexpected SQL activity from privileged accounts, and limit internet exposure of the server. No public PoC or KEV listing exists yet, but prioritize patching internet-facing ColdFusion instances given the critical base score.

9.11%
  • Adobe ColdFusion
largetens of thousands of internet-exposed ColdFusion servers (total installed base is larger but unreported)
CVE-2026-82004
Unauthenticated OS Command Injection in Adobe Campaign Classic

Adobe Campaign Classic (ACC) contains an OS command injection flaw (CWE-78) in which special elements passed to an operating system command are improperly neutralized, allowing attacker-supplied commands to run on the host. Per the CVSS vector, it is reachable over the network (AV:N), requires no privileges or user interaction, and has changed scope (S:C), meaning a successful attack can also affect resources beyond the vulnerable component. An attacker gains arbitrary code execution in the context of the current user, with high impact to confidentiality, integrity, and availability. Any organization running an affected Adobe Campaign Classic deployment is potentially exposed, though only instances reachable over the network are practically exploitable. No public proof-of-concept or confirmed in-the-wild exploitation is known, EPSS estimates a ~1.4% probability of exploitation within 30 days, and the fix arrived in a large Adobe patch release covering 170+ vulnerabilities.

Do: Upgrade Campaign Classic to the fixed build listed in Adobe's security bulletin for this CVE, since the affected and fixed version numbers are not included in the data provided. Until patched, limit network exposure of Campaign Classic application/web servers to trusted networks, as the flaw is exploitable without authentication or user interaction. Monitor for a public PoC or CISA KEV listing and review application service accounts for signs of unexpected command execution.

10.01%
  • Adobe Campaign Classic (ACC)
moderate~1,000-10,000 enterprise deployments worldwide (estimate; Adobe publishes no install counts)