By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Adobe Patches Magento Zero-Day Exploited for Backdoor

Adobe released critical security patches on Monday to address a maximum-severity vulnerability affecting Adobe Commerce and Magento Open Source, which has been actively exploited in the wild. The vulnerability, identified as CVE-2026-75650 with a CVSS score of 10.0, was discovered by Sansec and has been codenamed StyleSmuggler. Exploitation of this zero-day flaw began as early as September 4, 2026. Sansec's analysis indicates that attackers are leveraging this vulnerability to deploy a Rust-based backdoor and a PHP web shell on compromised Magento instances. The Rust backdoor is designed to establish persistent command-and-control (C2) communication, allowing attackers to maintain access and execute arbitrary commands on the affected servers. The PHP web shell provides a more direct interface for attackers to interact with the compromised system, enabling file manipulation, database access, and further reconnaissance. This active exploitation highlights the significant risk posed to businesses relying on Adobe Commerce and Magento Open Source platforms, underscoring the importance of prompt patching. Adobe Commerce is a leading e-commerce platform used by businesses of all sizes to build and manage online stores, offering a wide range of features for product management, order processing, and customer engagement. Magento Open Source is the free, community-driven version of the platform, providing flexibility and extensibility for developers. The severity of CVE-2026-75650, indicated by its perfect CVSS score of 10.0, means that the vulnerability is exploitable without requiring user interaction and can lead to complete system compromise. Sansec, the cybersecurity firm that identified the zero-day, has provided detailed technical analysis of the exploit chain, which involves bypassing security controls to gain unauthorized access. The discovery and subsequent patching of this vulnerability by Adobe demonstrate the ongoing cat-and-mouse game between cybersecurity researchers and malicious actors. Organizations running vulnerable versions of Adobe Commerce and Magento Open Source are urged to apply the provided patches immediately to mitigate the risk of compromise. Failure to do so could result in data breaches, financial losses, and reputational damage. The use of a Rust backdoor is notable, as Rust is a modern systems programming language known for its performance and memory safety, often favored for developing robust and efficient software, including malware. The PHP web shell is a common tool in web application attacks, providing attackers with a web-based interface to control compromised servers. The exploitation of this zero-day vulnerability underscores the persistent threat landscape for e-commerce platforms and the critical need for continuous security monitoring and rapid incident response.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.