CVE Tools

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

SecurityWeekBy Ionut Arghire

Reported exploitedAdobe CommerceSansecMagento Open Source

Our summary

Adobe has issued security updates for over 170 vulnerabilities across multiple products, including an urgent patch for a critical, actively exploited zero-day in Adobe Commerce and Magento Open Source. Tracked as CVE-2026-75650 with a perfect CVSS score of 10/10, this code injection flaw enables unauthenticated remote code execution and has been leveraged by threat actors, identified by Sansec research as StyleSmuggler, to backdoor online stores through the 'Payment Transaction Failed Reminder' feature. The vendor strongly advises administrators to apply the fixes immediately and rotate all encryption keys, administrative credentials, database access details, and API tokens at their source. Additional priority one patches were also distributed for Critical Command Injection issues in Campaign Classic and ColdFusion.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store