“Magento” — 32 distilled results

Adobe patches critical Magento zero-day exploited in attacks

A maximum-severity zero-day vulnerability called StyleSmuggler affecting Magento and Adobe Commerce was actively exploited starting September 4, 2026, to deploy Linux backdoors. Adobe released emergency patches (CVE-2026-75650) on September 8 after a three-day window of exposure.

CISA adds five known-exploited vulnerabilities to KEV catalog

Between September 24-25, 2026, the Cybersecurity and Infrastructure Security Agency added five actively exploited software vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Adobe Commerce/Magento, MikroTik RouterOS, Microsoft SharePoint, and WordPress Core. The vulnerabilities range from authorization bypass to remote code execution.

json:cisa-kev 5d ago

CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither fl

CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither flaw is known to be used in ransomware campaigns.