Urgent.News

What's breaking now, across thousands of outlets.

Tech

StyleSmuggler: Magento Zero-Day CVE-2026-75650 Drops a Rust Backdoor and a PHP Web Shell

TL;DR what: Adobe patched CVE-2026-75650, a CVSS 10.0 unauthenticated remote code execution flaw in Adobe Commerce and Magento Open Source that Sansec codenamed StyleSmuggler and observed being exploited as a zero-day from September 4, 2026. impact: Attackers get code execution as the web server with no credentials, and observed payloads include a Rust based Linux backdoor that beacons to an…

Adobe released a patch to fix a high-severity security vulnerability, CVE-2026-75650, found in Adobe Commerce and Magento Open Source platforms. This zero-day exploit allows attackers to execute code on the web server with no prior authentication, potentially leading to a complete compromise of the merchant's system. The flaw exists in the template system, where an attacker can inject malicious PHP code into a payment transaction email.

Once rendered, the code is executed without any user interaction. Adobe released an out-of-band patch on September 8, 2026, labeled as VULN-39341, which should be applied immediately to protect the store. Following the patch, it is crucial to rotate encryption keys to mitigate any potential risks from the attacker having access to stored payment configuration, integration tokens, and API credentials.

The vulnerability affects various versions of Adobe Commerce and Magento Open Source, and it is considered critical for any operation running the affected platforms.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Tuesday 8 September →