<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell]]></title><description><![CDATA[<p dir="auto">Adobe has shipped security updates to address a maximum-severity vulnerability in <strong>Adobe Commerce</strong> and <strong>Magento Open Source</strong> that is already being actively exploited in the wild.</p>
<p dir="auto">The flaw, tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75650" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-75650</a></strong> with a CVSS score of <strong>10.0</strong>, has been codenamed <strong>StyleSmuggler</strong> by security researchers at Sansec. The team discovered zero-day exploitation of the bug starting on <strong>September 4, 2026</strong>.</p>
<ul>
<li>Exploitation involves bypassing file upload restrictions to deliver a <strong>Rust-based backdoor</strong> and a <strong>PHP web shell</strong> onto affected servers.</li>
<li>Researchers observed the malware being used to establish persistent remote access and execute arbitrary commands on compromised e-commerce instances.</li>
</ul>
<p dir="auto">Adobe has classified the issue as critical and urges administrators to apply the latest patches immediately.</p>
<ul>
<li>Review server logs for suspicious file uploads or unexpected PHP payloads around the identified timeframe.</li>
<li>Audit user accounts with administrative privileges for unauthorized changes.</li>
<li>If compromise is suspected, rotate credentials and API keys, and scan for the presence of the Rust backdoor or web shell indicators.</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your team checked whether your Magento or Commerce deployment is exposed, and what steps are you taking to hunt for indicators before patching?</p>
]]></description><link>https://xploitlk.com/topic/260/critical-adobe-patches-magento-zero-day-exploited-to-deploy-rust-backdoor-and-php-web-shell</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:10:15 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/260.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 08 Sep 2026 10:30:32 GMT</pubDate><ttl>60</ttl></channel></rss>