importantSYS.SOURCE: The Hacker News• 2026-09-08T14:43:47+05:30
Adobe Addresses Critical Magento Zero-Day (CVE-2026-75650) Used for Rust Backdoor and PHP Web Shell Deployment
Adobe has released security patches for a critical zero-day vulnerability (CVE-2026-75650) in Magento and Adobe Commerce, actively exploited to deploy a Rust-based backdoor and PHP web shell. The U.S. CISA added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply fixes by September 11, 2026.
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.
The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.
"This update resolves a critical
*** END OF TRANSMISSION ***