Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Reported exploitedAdobe CommerceMagento Open SourceOur summary
Adobe has issued emergency patches for a critical remote code execution vulnerability affecting Adobe Commerce and Magento Open Source, confirmed to be under active attack. Tracked as CVE-2026-75650 with a maximum CVSS score of 10.0, this flaw allows attackers to execute arbitrary code by abusing the platform's template processing mechanisms.
Threat actors have already leveraged the zero-day to install persistent threats, including a custom Rust-based Linux backdoor and PHP web shells on compromised stores. To mitigate the risk, administrators must immediately apply the VULN-39341 hotfix and rotate all encryption keys across vulnerable versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.