importantSYS.SOURCE: The Hacker News• 2026-09-08T14:43:47+05:30
Adobe Addresses Critical Magento Zero-Day (CVE-2026-75650) Exploited for Rust Backdoor and PHP Web Shell Deployment
Adobe has released patches for a critical zero-day vulnerability (CVE-2026-75650) in Magento and Adobe Commerce, actively exploited to deploy a Rust backdoor and PHP web shell. The flaw allows arbitrary code execution through PHP code injection in Magento's template system, affecting multiple versions of the platform.
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.
The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.
"This update resolves a critical
*** END OF TRANSMISSION ***