Хакеры атаковали уязвимость StyleSmuggler в Magento и Adobe Commerce
Reported exploitedAdobe CommerceSansecMagento Open SourceOur summary
Security researchers at Sansec have disclosed that attackers are actively exploiting StyleSmuggler, a critical flaw identified as CVE-2026-75650 with a CVSS score of 10.0, in Magento Open Source and Adobe Commerce. This vulnerability enables unauthenticated remote code execution on the server by abusing the template engine to inject malicious PHP into system logs.
Affected versions include Adobe Commerce 2.4.4 through 2.4.9 and Magento Open Source 2.4.6 through 2.4.9. Following the confirmation of active attacks, Adobe released an emergency patch on September 8, 2026. Compromised servers typically exhibit a Rust-based backdoor disguised as legitimate Linux processes such as kworker, fc-cache, or chronyd.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.