CVE Tools

Хакеры атаковали уязвимость StyleSmuggler в Magento и Adobe Commerce

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedAdobe CommerceSansecMagento Open Source

Our summary

Security researchers at Sansec have disclosed that attackers are actively exploiting StyleSmuggler, a critical flaw identified as CVE-2026-75650 with a CVSS score of 10.0, in Magento Open Source and Adobe Commerce. This vulnerability enables unauthenticated remote code execution on the server by abusing the template engine to inject malicious PHP into system logs.

Affected versions include Adobe Commerce 2.4.4 through 2.4.9 and Magento Open Source 2.4.6 through 2.4.9. Following the confirmation of active attacks, Adobe released an emergency patch on September 8, 2026. Compromised servers typically exhibit a Rust-based backdoor disguised as legitimate Linux processes such as kworker, fc-cache, or chronyd.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store