MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-08 · via BleepingComputer

Adobe Releases Emergency Patch for Actively Exploited Magento Backdoor Flaw

Image via BleepingComputer
Image via BleepingComputer

Adobe has issued an emergency hotfix for CVE-2026-75650, a maximum-severity zero-day in Magento and Adobe Commerce that has been exploited since at least September 4 to plant backdoors. The flaw, named StyleSmuggler, allows arbitrary code execution, and attackers have used it to hide command-and-control traffic as NTP requests. Adobe urges immediate installation of the hotfix and recommends rotating all credentials and secrets after patching.

Expanded Detail

Sansec's investigation revealed the backdoor concealed its command-and-control traffic within NTP requests, while affected stores emitted "Payment Transaction Failed Reminder" emails as a distinct indicator. Adobe's hotfix, VULN-39341, has only been validated against the August 2026 releases of the impacted product branches.

A second threat actor has since exploited the flaw to install a 485-byte PHP web shell that checks the pub/media directory for write access and exfiltrates data to an oast.site domain. With exploitation escalating, the vendor advises rotating all administrative, API, and database credentials following the patch.

Context

E-commerce operators using affected Adobe Commerce or Magento versions could face severe operational disruption and financial loss. The backdoor's persistence may allow attackers to steal customer payment data or manipulate transactions, potentially exposing shoppers to fraud. The required credential rotation across databases, SSH, and APIs could cause significant downtime for merchants. As exploitation escalates, unpatched stores may become increasingly targeted, impacting the broader digital retail ecosystem's trust and security.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Unpatched Magento flaw exploited to plant stealthy Linux backdoor · Cybersecurity
Emergency hotfix issued for critical N-central remote code execution bug · Cybersecurity
Google Urges Immediate Chrome Update to Patch 12 Vulnerabilities · Cybersecurity
Chrome Update Fixes Actively Exploited V8 Flaw · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Adobe fixes critical Magento zero-day exploited to backdoor servers.” Browse more stories.