Critical Adobe Commerce Zero-Day CVE-2026-75650 Exploited to Deploy Rust Backdoor
A critical unauthenticated remote code execution vulnerability, tracked as CVE-2026-75650 and dubbed StyleSmuggler, affects Adobe Commerce and Magento Open Source installations. Discovered and reported by Sansec, the flaw allows attackers to inject PHP into the template system, which then executes when the server renders a failed payment notification email — requiring no user interaction. Active exploitation has been observed deploying a Rust-based Linux backdoor, with some variants also dropping PHP web shells; the malware communicates via WebSocket over TLS or NTP-like UDP traffic on port 123. Adobe has released a hotfix under security bulletin APSB26-146, though applying it does not remove existing malware or invalidate credentials that may already have been compromised. Store operators are advised to apply the patch immediately, audit templates, check for unauthorized files under pub/media, and review processes and cron entries for signs of compromise.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in