LmCast :: Stay tuned in

Adobe fixes critical Magento zero-day exploited to backdoor servers

Recorded: Sept. 8, 2026, 2:08 p.m.

Original Summarized

Adobe fixes critical Magento zero-day exploited to backdoor servers

News

Featured
Latest

Trezor data breach impact now reaches 81,000 customers

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

N-able patches max severity N-central flaw amid ongoing attacks

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Adobe fixes critical Magento zero-day exploited to backdoor servers

Webinar: The forgotten Google Workspace access that can lead to a breach

Hackers build AI frameworks for widescale credential theft

Microsoft: Windows Server 2025 changes causing app crashes

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityAdobe fixes critical Magento zero-day exploited to backdoor servers

Adobe fixes critical Magento zero-day exploited to backdoor servers

By Bill Toulas

September 8, 2026
09:34 AM
0

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.
E-commerce security company Sansec discovered that the flaw has been leveraged in attacks since at least September 4 to plant a backdoor on vulnerable websites.
The backdoor disguised its command-and-control (C2) host as a regular Network Time Protocol (NTP) server. However, it still leaves distinct signs of activity on compromised hosts, such as "Payment Transaction Failed Reminder" emails.
In an update yesterday, Adobe pushed a security fix that addresses the StyleSmuggler vulnerability in Adobe Commerce and Magento.
“This update resolves a critical vulnerability that could result in arbitrary code execution. Adobe is aware of CVE-2026-75650 being exploited in the wild,” reads the security advisory.
Adobe notes that the flaw impacts the following versions of its e-commerce products:
Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch
The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.
After installing the hotfix, administrators should enable maintenance mode, suspend cron jobs, and rotate all secrets, including administrator passwords, GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH keys, and API keys.
After rotation, it is recommended to flush the cache, restore cron execution, and disable maintenance mode.
Adobe says the hotfix has only been tested against the August 2026 releases of the affected product branches, and while it may work with other releases, compatibility with them has not been confirmed.
In an update to its original report, Sansec says that a second attacker with unrelated tooling has been observed exploiting CVE-2026-75650 to deploy a 485-byte PHP web shell.
The malware collects basic server details, checks whether the pub/media location is writable, and exfiltrates the data through requests to an oast.site subdomain, which is typically seen in security tests that use the Interactsh open-source tool.
Because exploitation activity has increased, administrators are strongly advised to apply Adobe's hotfix or mitigations as soon as possible.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
Magento StyleSmuggler zero-day exploited to deploy Linux backdoorHackers exploit critical Adobe Commerce flaw to hijack customer accountsN-able patches max severity N-central flaw amid ongoing attacksCritical Elementor Pro flaw exploited to take over WordPress sitesHackers exploit Sangoma Switchvox flaw to deploy reverse shells

Actively Exploited
Adobe
Backdoor
E-Commerce
Hotfix
Magento
Remote Code Execution

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Sponsor Posts

Unify ransomware protection and recovery for every client

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

CTI Starter Kit + 2026 SANS CTI Survey

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Adobe released an emergency security update addressing CVE-2026-75650, a critical zero-day vulnerability known as StyleSmuggler, which affects multiple versions of Magento and Adobe Commerce products. Security research from Sansec indicated that this flaw had been actively exploited since at least September 4 to facilitate the planting of backdoors on vulnerable websites. The initial exploitation involved disguising the command-and-control (C2) host as a legitimate Network Time Protocol (NTP) server, although distinct signs of compromise, such as "Payment Transaction Failed Reminder" emails, remained observable on affected systems.

Adobe addressed this vulnerability by deploying a security fix that mitigates the risk of arbitrary code execution. The flaw impacts specific versions across their e-commerce offerings, including Adobe Commerce versions 2.4.4 through 2.4.9, Adobe Commerce B2B versions 1.3.3 through 1.5.3, and Magento Open Source versions 2.4.6 through 2.4.9, encompassing releases up to August 2026. Given the active exploitation, Adobe prioritized this update, recommending that administrators immediately install the VULN-39341 hotfix.

Following the installation of the hotfix, security professionals are advised to implement comprehensive mitigation strategies. This involves enabling maintenance mode and suspending cron jobs, followed by rotating all sensitive credentials, including administrator passwords, GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH keys, and API keys. After credential rotation, it is recommended to flush the cache and restore cron execution, while keeping maintenance mode disabled. In addition to this fix, subsequent reports indicated a secondary exploitation where another attacker utilized unrelated tooling to deploy a 485-byte PHP web shell on compromised systems. This malware was capable of collecting basic server details, verifying write permissions in the pub/media directory, and exfiltrating data through requests made to an oast.site subdomain, a technique frequently observed in security tests using tools like Interactsh. Due to the increased exploitation activity, applying the hotfix or implementing these mitigations promptly is strongly advised for administrators managing affected environments.