⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

September 8, 2026

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell Ravie LakshmananSep 08, 2026Vulnerability / Web Security Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical vulnerability that could result in arbitrary code execution," Adobe said, adding it's "aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants." At its core, the flaw abuses Magento's template system through PHP code injection to generate a "Payment Transaction Failed Reminder"…

CVEs: CVE-2026-75650