Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
What happened
Adobe released a hotfix for CVE-2026-75650, a maximum-severity vulnerability in Adobe Commerce and Magento Open Source that Sansec identified as being actively exploited since September 4, 2026. The flaw, dubbed StyleSmuggler, allows unauthenticated attackers to inject PHP code into the template system to achieve remote code execution. Threat actors have used this vulnerability to deploy a Rust-based Linux backdoor and a PHP web shell on compromised e-commerce servers.
Why it ranks #1
Adobe released a hotfix for CVE-2026-75650, a maximum-severity vulnerability in Adobe Commerce and Magento Open Source that Sansec identified as being actively exploited since September 4, 2026.
Who should care
IT and platform operations, SOC and incident response teams
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- emerging