Adobe patches critical Magento zero-day exploited in attacks

A maximum-severity zero-day vulnerability called StyleSmuggler affecting Magento and Adobe Commerce was actively exploited starting September 4, 2026, to deploy Linux backdoors. Adobe released emergency patches (CVE-2026-75650) on September 8 after a three-day window of exposure.

28 reports · 27 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

StyleSmuggler zero-day targets Magento Open Source and Adobe Commerce with unauthenticated RCE. Active since Sept. 4, no patch or advisory from Adobe. Merchants remain https:// deafnews.it/en/article/

mastodon:infosec-exchangeother24d ago kagi ↗

StyleSmuggler zero-day targets Magento Open Source and Adobe Commerce with unauthenticated RCE. Active since Sept. 4, no patch or advisory from Adobe. Merchants remain https:// deafnews.it/en/article/stylesm uggler-zero-day-magento-under-attack-since-sept-4-no-patch-available

🔹 The Hacker News Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce th

mastodon:infosec-exchangeother24d ago kagi ↗

🔹 The Hacker News Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw

⚠️ CRITICAL: Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores A zero-day vulnerability called StyleSmuggler in Magento Open Source and Adobe Commerce is being actively

mastodon:infosec-exchangeother24d ago kagi ↗

⚠️ CRITICAL: Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores A zero-day vulnerability called StyleSmuggler in Magento Open Source and Adobe Commerce is being actively exploited to achieve unauthenticated remote code execution and install persistent backdoors. All current versions are affected. Threat actors began attacks before public disclosure, meaning you… http

The watchTowr team is rapidly reacting to "StyleSmuggler", a zero-day RCE in Magento and Adobe Commerce already under active exploitation. Magento vulns have a history of rapid mass exploitation - exp

mastodon:infosec-exchangeother24d ago kagi ↗

The watchTowr team is rapidly reacting to "StyleSmuggler", a zero-day RCE in Magento and Adobe Commerce already under active exploitation. Magento vulns have a history of rapid mass exploitation - expect this to be no different. Disable GraphQL, and reach out if you need help.

🤖 Unpatched Magento/Adobe Commerce zero-day "StyleSmuggler" exploited in the wild: unauthenticated code execution on store servers, attacks since Sep 4. No patch available; Sansec recommends auditing

mastodon:infosec-exchangeother24d ago kagi ↗

🤖 Unpatched Magento/Adobe Commerce zero-day "StyleSmuggler" exploited in the wild: unauthenticated code execution on store servers, attacks since Sep 4. No patch available; Sansec recommends auditing store code for backdoors. 🔗 https:// thehackernews.com/2026/09/unpa tched-magento-and-adobe-commerce.html # CyberSec # 0day # Magento # Ecommerce

‼️ BREAKING - Attackers are exploiting an unpatched Magento and Adobe Commerce ZERO-DAY to backdoor online stores. No login required. No published CVE. No Adobe patch yet. Here's what to do and how th

mastodon:infosec-exchangeother24d ago kagi ↗

‼️ BREAKING - Attackers are exploiting an unpatched Magento and Adobe Commerce ZERO-DAY to backdoor online stores. No login required. No published CVE. No Adobe patch yet. Here's what to do and how the attack works: https:// thehackernews.com/2026/09/unpa tched-magento-and-adobe-commerce.html

Unauthenticated zero-day RCE "StyleSmuggler" is actively exploiting Magento and Adobe Commerce stores since Sept 4. No patch, CVE, or workaround from Adobe as of Sept 6. Merchants https:// deafnews.it

mastodon:infosec-exchangeother23d ago kagi ↗

Unauthenticated zero-day RCE "StyleSmuggler" is actively exploiting Magento and Adobe Commerce stores since Sept 4. No patch, CVE, or workaround from Adobe as of Sept 6. Merchants https:// deafnews.it/en/article/stylesm uggler-hits-magento-unpatched-rce-stores-already-compromised

🤖 Unpatched Magento Open Source & Adobe Commerce 0-day ("StyleSmuggler") exploited in the wild since Sep 4: unauthenticated code execution on store servers, used to backdoor online shops. Sansec advi

mastodon:infosec-exchangeother23d ago kagi ↗

🤖 Unpatched Magento Open Source & Adobe Commerce 0-day ("StyleSmuggler") exploited in the wild since Sep 4: unauthenticated code execution on store servers, used to backdoor online shops. Sansec advisory. 🔗 https:// thehackernews.com/2026/09/unpa tched-magento-and-adobe-commerce.html # CVE # 0day # CyberSec

A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. https://www. bleepingcomputer.com/news/secu rit

mastodon:infosec-exchangeother22d ago kagi ↗

A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. https://www. bleepingcomputer.com/news/secu rity/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/

Magento zero-day exploited despite full patching A critical unpatched flaw in Magento and Adobe Commerce allows RCE without authentication. https:// hostingpaper.com/article/magen to-zero-day-exploite

mastodon:mstdn-socialother22d ago kagi ↗

Magento zero-day exploited despite full patching A critical unpatched flaw in Magento and Adobe Commerce allows RCE without authentication. https:// hostingpaper.com/article/magen to-zero-day-exploited-despite-full-patching # Security # Vulnerabilities

🤖 Magento StyleSmuggler 0-day exploited in the wild: PHP code injection in the template system triggers a fake failed-payment email → code execution. Drops a Rust backdoor disguised as kworker/fc-cac

mastodon:infosec-exchangeother22d ago kagi ↗

🤖 Magento StyleSmuggler 0-day exploited in the wild: PHP code injection in the template system triggers a fake failed-payment email → code execution. Drops a Rust backdoor disguised as kworker/fc-cache, C2 masked as NTP (UDP 123), 30-min cron persistence. No patch yet; Adobe fix expected Sept 8. 🔗 https://www. bleepingcomputer.com/news/secu rity/magento-stylesmuggler-zero-day-exploited-to-deploy

🤖 Magento "StyleSmuggler" zero-day exploited in the wild: affects all versions of Magento and Adobe Commerce. Attacks since Sept 4 deploy a Linux backdoor; no CVE ID published yet. Apply the Adobe ad

mastodon:infosec-exchangeother21d ago kagi ↗

🤖 Magento "StyleSmuggler" zero-day exploited in the wild: affects all versions of Magento and Adobe Commerce. Attacks since Sept 4 deploy a Linux backdoor; no CVE ID published yet. Apply the Adobe advisory, audit for compromise. 🔗 https://www. bleepingcomputer.com/news/secu rity/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/ # CVE # Exploit # 0day # CyberSec

StyleSmuggler Zero-Day Exploits Adobe Commerce and Magento Template Systems Attackers are exploiting a zero-day vulnerability called StyleSmuggler in Adobe Commerce and Magento to execute remote code

mastodon:infosec-exchangeother21d ago kagi ↗

StyleSmuggler Zero-Day Exploits Adobe Commerce and Magento Template Systems Attackers are exploiting a zero-day vulnerability called StyleSmuggler in Adobe Commerce and Magento to execute remote code and install Rust-based backdoors. The flaw bypasses recent security patches by injecting malicious PHP into the template system via failed payment email rendering. **If you run Magento or Adobe Commer

Adobe fixes exploited Magento zero-day affecting online stores

kite:cybersecurityother21d ago kagi ↗

Adobe released emergency fixes for CVE-2026-75650, a maximum-severity zero-day in Adobe Commerce and Magento Open Source that attackers have exploited against online merchants [thehackernews.com#1][bleepingcomputer.com#1][securityweek.com#1]. The flaw, dubbed StyleSmuggler by Sansec, has a CVSS score of 10.0 and allows unauthenticated remote code execution through a code injection issue [thehacker

The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. https:// thehackerne

mastodon:infosec-exchangeother21d ago kagi ↗

The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. https:// thehackernews.com/2026/09/adob e-patches-magento-zero-day.html

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. ht

mastodon:infosec-exchangeother21d ago kagi ↗

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. https://www. bleepingcomputer.com/news/secu rity/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/

Adobe patches exploited Magento zero-day CVE-2026-75650 Critical flaw in Adobe Commerce and Magento allowed server backdoors via StyleSmuggler exploit. https:// hostingpaper.com/article/adobe -patches

mastodon:mstdn-socialother21d ago kagi ↗

Adobe patches exploited Magento zero-day CVE-2026-75650 Critical flaw in Adobe Commerce and Magento allowed server backdoors via StyleSmuggler exploit. https:// hostingpaper.com/article/adobe -patches-exploited-magento-zero-day-cve-2026-75650 # Security # Vulnerabilities

🤖 CVE-2026-75650 (StyleSmuggler): max-severity Adobe Commerce/Magento zero-day, exploited in the wild since Sep 4. Backdoor hides its C2 as an NTP server; a second actor deploys a 485-byte PHP web sh

mastodon:infosec-exchangeother21d ago kagi ↗

🤖 CVE-2026-75650 (StyleSmuggler): max-severity Adobe Commerce/Magento zero-day, exploited in the wild since Sep 4. Backdoor hides its C2 as an NTP server; a second actor deploys a 485-byte PHP web shell. Emergency patch (VULN-39341) released. 🔗 https://www. bleepingcomputer.com/news/secu rity/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/ # CVE # 0day # CyberSec

🤖 CVE-2026-75650 (CVSS 10.0): Adobe Commerce & Magento 0-day "StyleSmuggler" exploited in the wild since Sep 4, 2026. Unauthenticated flaw used to deploy a Rust backdoor + PHP web shell. Sansec disco

mastodon:infosec-exchangeother21d ago kagi ↗

🤖 CVE-2026-75650 (CVSS 10.0): Adobe Commerce & Magento 0-day "StyleSmuggler" exploited in the wild since Sep 4, 2026. Unauthenticated flaw used to deploy a Rust backdoor + PHP web shell. Sansec discovered it; patches released. 🔗 https:// thehackernews.com/2026/09/adob e-patches-magento-zero-day.html # CVE # 0day # CyberSec

Adobe patches StyleSmuggler, an actively exploited Magento zero-day with maximum CVSS 10.0 severity. CISA added CVE-2026-75650 to its catalog; federal agencies must https:// deafnews.it/en/article/ado

mastodon:infosec-exchangeother20d ago kagi ↗

Adobe patches StyleSmuggler, an actively exploited Magento zero-day with maximum CVSS 10.0 severity. CISA added CVE-2026-75650 to its catalog; federal agencies must https:// deafnews.it/en/article/adobe-p atches-stylesmuggler-actively-exploited-magento-zero-day-with-cvss-100

Sansec reports active exploitation since Sept 4 of StyleSmuggler, a Magento/Adobe Commerce zero-day enabling unauthenticated remote code execution. Attackers are installing Linux backdoors for persist

mastodon:infosec-exchangeother20d ago kagi ↗

Sansec reports active exploitation since Sept 4 of StyleSmuggler, a Magento/Adobe Commerce zero-day enabling unauthenticated remote code execution. Attackers are installing Linux backdoors for persistent server control, exposing e-commerce infrastructure to data theft. # Magento # AdobeCommerce # ZeroDay https:// cyberworldops.eu/en/stylesmugg ler-zero-day-gives-attackers-remote-control-of-patched

Magento and Adobe Commerce shops had three days of exposure last week. Sansec, a Dutch e-commerce security firm, found a template injection flaw being exploited on 4 September: unauthenticated code ex

mastodon:infosec-exchangeother20d ago kagi ↗

Magento and Adobe Commerce shops had three days of exposure last week. Sansec, a Dutch e-commerce security firm, found a template injection flaw being exploited on 4 September: unauthenticated code execution, CVSS 10, versions 2.4.4 through 2.4.9. Adobe's emergency fix landed on the 7th and CISA catalogued it as known-exploited on the 8th. On a CVSS 10 the patching question answers itself. The har