A maximum-severity zero-day in Adobe Commerce and Magento let attackers take over online stores without logging in
A CVSS 10.0 flaw in Adobe $ADBE Commerce and Magento, dubbed StyleSmuggler, was exploited in the wild from September 4 to plant backdoors before Adobe shipped a fix on September 7. Per The Hacker News / BleepingComputer.
A maximum-severity vulnerability in Adobe $ADBE Commerce and Magento Open Source, tracked as CVE-2026-75650 and nicknamed StyleSmuggler, let unauthenticated attackers execute code on victim stores by abusing Magento's template system through a 'Payment Transaction Failed Reminder' email. Security firm Sansec found exploitation in the wild starting September 4, 2026, days before Adobe released an emergency hotfix on September 7. Investigators identified two separate payloads on compromised stores: a Rust-based Linux backdoor disguising its command-and-control traffic as NTP server communication, and a 485-byte PHP web shell. The US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on September 8, ordering federal agencies to patch by September 11. Sources: The Hacker News, BleepingComputer.