Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
- ID
- 22287
- Status
- summarized
- Published
- 08 Sep 2026, 5:13 PM
- Fetched
- 08 Sep 2026, 5:56 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.0
- Created
- 08 Sep 2026, 5:57 PM
- Tags
- Audience
- developerssaas_startup_founders
What happened
Adobe has patched CVE-2026-75650 (CVSS 10.0), a maximum-severity zero-day in Adobe Commerce and Magento Open Source actively exploited since September 4, 2026. Dubbed 'StyleSmuggler' by Sansec, the flaw abuses Magento's template system via PHP code injection in transaction-failed reminder emails, enabling attackers to deploy a Rust-based Linux backdoor and a PHP web shell. Adobe requires affected merchants to apply the VULN-39341 patch and rotate encryption keys.
Why it matters
If you operate or maintain any Adobe Commerce or Magento Open Source store on versions 2.4.4 through 2.4.9 (August 2026 builds or earlier), apply the VULN-39341 composer patch and rotate your encryption keys now — one compromised server was hit 50 minutes after the first confirmed exploit. Malaysian and SEA e-commerce teams commonly run Magento, so this is an immediate operational priority, not a watch-and-wait item.
Discussion angle
How many Malaysian e-commerce sites are still on unpatched Magento builds, and what's the realistic patch lead time for small teams managing their own Commerce instances versus hosted platforms?