CVE Tools

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

The Hacker NewsBy The Hacker News

Reported exploitedAdobe CommerceMagento Open Source

Our summary

Adobe has issued emergency patches for a critical remote code execution vulnerability affecting Adobe Commerce and Magento Open Source, confirmed to be under active attack. Tracked as CVE-2026-75650 with a maximum CVSS score of 10.0, this flaw allows attackers to execute arbitrary code by abusing the platform's template processing mechanisms.

Threat actors have already leveraged the zero-day to install persistent threats, including a custom Rust-based Linux backdoor and PHP web shells on compromised stores. To mitigate the risk, administrators must immediately apply the VULN-39341 hotfix and rotate all encryption keys across vulnerable versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store