CVE Tools

Adobe fixes critical Magento zero-day exploited to backdoor servers

BleepingComputerBy Bill Toulas

Reported exploitedPlex Media ServerSansecPlex Desktop

Our summary

Adobe has issued an emergency update to address CVE-2026-75650, a critical zero-day flaw in Magento and Adobe Commerce that is currently being leveraged to deploy backdoors on compromised servers. E-commerce security firm Sansec identified active exploitation of this vulnerability, referred to as StyleSmuggler, starting in early September, where attackers used it to install persistent access mechanisms disguised as NTP servers. Affected products include Adobe Commerce versions 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.6 through 2.4.9.

The vendor has released the VULN-39341 hotfix to resolve this arbitrary code execution issue. Administrators are urged to apply the patch immediately and subsequently rotate all administrative credentials, API keys, and secrets to mitigate potential compromise.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store