← All stories
● Covered by 3 sources · 6 reportsHigh impact3 negative3 neutral

Unpatched Magento and Adobe Commerce Zero-Day Actively Exploited to Backdoor Online Stores

🔄 Updated 23d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • New zero-day vulnerability "StyleSmuggler" exploited in Magento/Adobe Commerce.
  • Allows unauthenticated code execution and persistent backdoor installation.
  • All current versions, including 2.4.9, are affected.
  • Adobe has not released a patch or advisory as of September 6.
  • Sansec reported the exploitation of the vulnerability.
  • Attackers inject PHP code into Magento's template system using 'styles' properties.
  • Attack works in two stages: PHP code injected via failure report, then executed via failed payment email.
  • The RCE flaw works on Magento versions 2.4.7 and 2.4.8.
  • Exploited against deployments running July and August 2026 patches.
  • Backdoor is written in Rust and connects to a command-and-control server.
  • Exploitation started on September 4.
  • Backdoor disguised as '[kworker/u:8:0]'.
  • A second backdoor version emerged on September 6, disguised as 'fc-cache'.
  • Malware hides C&C communication as NTP server replies.
  • Adobe Enterprise Support confirmed working on a fix, no timeline given.
  • Magento is installed on over 160,000 websites.
  • Newer backdoor versions copy to ~/.cache/fontconfig/fc-cache.
  • Attacker adds a cron job to repeat every 30 minutes for persistence.
  • Adobe released security patches on Monday.
  • The vulnerability is tracked as CVE-2026-75650.
  • CVE-2026-75650 has a CVSS score of 10.0.
  • The flaw affects Adobe Commerce versions 2.4.9-2026-aug and earlier.
  • The flaw affects Adobe Commerce versions 2.4.8-2026-aug and earlier.
  • The flaw affects Adobe Commerce versions 2.4.7-2026-aug and earlier.
  • The flaw affects Adobe Commerce versions 2.4.6-2026-aug and earlier.
  • The flaw affects Adobe Commerce versions 2.4.5-2026-aug and earlier.
  • The flaw affects Adobe Commerce versions 2.4.4-2026-aug and earlier.
  • The flaw affects Adobe Commerce B2B versions 1.5.3-2026-aug and earlier.
  • The flaw affects Adobe Commerce B2B versions 1.5.2-2026-aug and earlier.
  • The flaw affects Adobe Commerce B2B versions 1.4.2-2026-aug and earlier.
  • The flaw affects Adobe Commerce B2B versions 1.3.4-2026-aug and earlier.
  • The flaw affects Adobe Commerce B2B versions 1.3.3-2026-aug and earlier.
  • The flaw affects Magento Open Source version 2.4.9-2026-aug.
  • Adobe patched over 170 vulnerabilities across its products.
  • Adobe published a KB article with details on the update.
  • Users should rotate encryption keys and credentials.

Active Exploitation of New Zero-Day

Dutch e-commerce security company Sansec reported on September 5 that attackers are actively exploiting a new, unpatched vulnerability in Magento Open Source and Adobe Commerce. This zero-day, dubbed "StyleSmuggler," allows malicious code execution on an online store's server without requiring authentication. Sansec discovered the flaw and noted that attacks began on September 4, prompting an early public disclosure due to ongoing compromises.

Vulnerability Details and Impact

A successful exploit of StyleSmuggler grants attackers code execution privileges on the server and installs a persistent backdoor. Sansec confirmed that all current versions of Magento Open Source are affected, including 2.4.9, and successfully reproduced the unauthenticated chain on clean installations of versions 2.4.7, 2.4.8, and 2.4.9. The first identified victim was running version 2.4.6-p15 with the latest available security updates from Adobe.

Adobe's Response and Interim Advice

As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround for the StyleSmuggler vulnerability. Adobe's next scheduled security release is on September 8, but it is unknown if this bug will be addressed. Sansec's interim advice for affected stores is to temporarily disable GraphQL until a fix is released. Disrex Group, a Magento hosting company, independently confirmed exploitation on two compromised Magento Open Source stores, noting that headless and progressive web app storefronts typically require GraphQL.

Updates

🕒 2026-09-08 · new reporting from SecurityWeek
  • Adobe patched over 170 vulnerabilities across its products.
  • Adobe published a KB article with details on the update.
  • Users should rotate encryption keys and credentials.
🕒 2026-09-08 · new reporting from The Hacker News
  • Adobe released security patches on Monday.
  • The vulnerability is tracked as CVE-2026-75650.
  • CVE-2026-75650 has a CVSS score of 10.0.
  • The flaw affects Adobe Commerce versions 2.4.9-2026-aug and earlier.
  • The flaw affects Adobe Commerce versions 2.4.8-2026-aug and earlier.
  • The flaw affects Adobe Commerce versions 2.4.7-2026-aug and earlier.
  • The flaw affects Adobe Commerce versions 2.4.6-2026-aug and earlier.
  • The flaw affects Adobe Commerce versions 2.4.5-2026-aug and earlier.
  • The flaw affects Adobe Commerce versions 2.4.4-2026-aug and earlier.
  • The flaw affects Adobe Commerce B2B versions 1.5.3-2026-aug and earlier.
  • The flaw affects Adobe Commerce B2B versions 1.5.2-2026-aug and earlier.
  • The flaw affects Adobe Commerce B2B versions 1.4.2-2026-aug and earlier.
  • The flaw affects Adobe Commerce B2B versions 1.3.4-2026-aug and earlier.
  • The flaw affects Adobe Commerce B2B versions 1.3.3-2026-aug and earlier.
  • The flaw affects Magento Open Source version 2.4.9-2026-aug.
🕒 2026-09-07 · new reporting from BleepingComputer
  • Adobe Enterprise Support confirmed working on a fix, no timeline given.
  • Magento is installed on over 160,000 websites.
  • Newer backdoor versions copy to ~/.cache/fontconfig/fc-cache.
  • Attacker adds a cron job to repeat every 30 minutes for persistence.
🕒 2026-09-07 · new reporting from SecurityWeek
  • Sansec reported the exploitation of the vulnerability.
  • Attackers inject PHP code into Magento's template system using 'styles' properties.
  • Attack works in two stages: PHP code injected via failure report, then executed via failed payment email.
  • The RCE flaw works on Magento versions 2.4.7 and 2.4.8.
  • Exploited against deployments running July and August 2026 patches.
  • Backdoor is written in Rust and connects to a command-and-control server.
  • Exploitation started on September 4.
  • Backdoor disguised as '[kworker/u:8:0]'.
  • A second backdoor version emerged on September 6, disguised as 'fc-cache'.
  • Malware hides C&C communication as NTP server replies.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Adobe released patches for over 170 vulnerabilities across its products, including a critical zero-day code injection flaw (CVE-2026-75650) in Adobe Commerce and Magento Open Source that has been actively exploited. The vulnerability allows unauthenticated remote code execution and has been used by attackers to deploy backdoors and web shells in online stores. Users are advised to apply fixes immediately and rotate encryption keys and credentials.

Adobe released an emergency security fix for CVE-2026-75650, a critical zero-day vulnerability dubbed StyleSmuggler, affecting multiple versions of Magento and Adobe Commerce. This flaw has been actively exploited since at least September 4 to install backdoors on vulnerable e-commerce servers, allowing for arbitrary code execution.

Adobe released security patches for a critical zero-day vulnerability, CVE-2026-75650, affecting Adobe Commerce and Magento Open Source, which has been actively exploited since September 4, 2026. This flaw allows arbitrary code execution through PHP code injection in Magento's template system, leading to the deployment of Rust backdoors and PHP web shells on compromised e-commerce sites.

A zero-day vulnerability named "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is actively being exploited to install a Rust-based Linux backdoor. This vulnerability allows attackers to inject PHP code through Magento's template system, leading to code execution and persistence on affected e-commerce sites.

A zero-day vulnerability, dubbed StyleSmuggler, in Adobe Commerce and Magento e-commerce platforms is being actively exploited to inject PHP code and install backdoors on online stores. This flaw allows attackers to achieve remote code execution without user interaction, posing a significant risk to affected e-commerce businesses.

A new unpatched zero-day vulnerability, named StyleSmuggler, in Magento Open Source and Adobe Commerce is being actively exploited to install backdoors on online store servers. The flaw allows attackers to execute malicious code without authentication, affecting all current versions including 2.4.9. Adobe has not yet released a patch or advisory, leaving stores vulnerable to compromise.