Critical Magento Zero-Day CVE-2026-75650 Exploited Before Patch, Rust Backdoor Deployed
Adobe released an emergency out-of-band patch on September 8, 2026 for CVE-2026-75650, a maximum-severity CVSS 10.0 unauthenticated remote code execution vulnerability affecting Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9. Security firm Sansec, which named the flaw StyleSmuggler, confirmed attackers began exploiting it four days earlier on September 4, giving them a head start on unpatched merchants. The vulnerability resides in Magento's template system and allows a single unauthenticated HTTP request to execute arbitrary code by injecting PHP through the email template path used for payment failure reminders. Observed payloads include a Rust-based Linux backdoor that communicates with an external server and a PHP web shell capable of writing arbitrary code to checkout hosts. Adobe's advisory requires merchants to apply the VULN-39341 hotfix from repo.magento.com and mandatorily rotate encryption keys, as the keys protect stored payment configurations, API credentials, and integration tokens that may have been exposed during the zero-day window.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in