🔴 Critical: Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
-
Adobe has shipped security updates to address a maximum-severity vulnerability in Adobe Commerce and Magento Open Source that is already being actively exploited in the wild.
The flaw, tracked as CVE-2026-75650 with a CVSS score of 10.0, has been codenamed StyleSmuggler by security researchers at Sansec. The team discovered zero-day exploitation of the bug starting on September 4, 2026.
- Exploitation involves bypassing file upload restrictions to deliver a Rust-based backdoor and a PHP web shell onto affected servers.
- Researchers observed the malware being used to establish persistent remote access and execute arbitrary commands on compromised e-commerce instances.
Adobe has classified the issue as critical and urges administrators to apply the latest patches immediately.
- Review server logs for suspicious file uploads or unexpected PHP payloads around the identified timeframe.
- Audit user accounts with administrative privileges for unauthorized changes.
- If compromise is suspected, rotate credentials and API keys, and scan for the presence of the Rust backdoor or web shell indicators.
Source: The Hacker News
Has your team checked whether your Magento or Commerce deployment is exposed, and what steps are you taking to hunt for indicators before patching?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login