Written by 2:01 pm Security Views: 0

Magento Adobe Commerce Zero-Day Exploited in Active Attacks

Magento Adobe Commerce zero-day CVE-2026-75650

A Magento Adobe Commerce zero-day is being exploited in active attacks against online stores. The vulnerability is tracked as CVE-2026-75650 and has a critical CVSS score of 10.0.

Adobe says the flaw can allow attackers to execute arbitrary code without authentication. Security researchers have also observed attacks that can install backdoors on compromised stores.

What Is the Magento Adobe Commerce Zero-Day?

The Magento Adobe Commerce zero-day is a critical vulnerability in the template engine.

Adobe classifies the flaw as an improper neutralization issue. It can lead to arbitrary code execution.

The vulnerability does not require user authentication. This makes internet-facing stores a major target.

Security researchers call the attack technique StyleSmuggler. Attacks were first confirmed on September 4, 2026.

How the Magento Adobe Commerce Zero-Day Attack Works

StyleSmuggler abuses Magento’s template system.

Attackers can inject malicious PHP code into the application. The attack can then trigger Magento to process the injected code.

Researchers found that attackers can abuse failed payment email processing as part of the attack chain.

The technique allows attackers to execute code without having valid store credentials.

Magento Adobe Commerce Zero-Day Can Install Backdoors

A successful attack can give criminals control over a compromised server.

Security researchers found a Rust-based backdoor during their investigation.

The malware has used process names such as [kworker/u:8:0], fc-cache, and chronyd. These names can make malicious processes look like normal Linux processes.

Researchers also found persistence mechanisms involving cron jobs.

This means removing the original vulnerability alone may not be enough.

Store owners should also check their systems for signs of compromise.

Which Magento and Adobe Commerce Versions Are Affected?

Adobe says the vulnerability affects multiple supported Adobe Commerce and Magento Open Source versions.

Affected Adobe Commerce versions include:

  • 2.4.4-2026-aug and earlier
  • 2.4.5-2026-aug and earlier
  • 2.4.6-2026-aug and earlier
  • 2.4.7-2026-aug and earlier
  • 2.4.8-2026-aug and earlier
  • 2.4.9-2026-aug and earlier

Magento Open Source versions from 2.4.6 through 2.4.9 are also listed as affected.

Adobe Commerce B2B versions are also included in Adobe’s advisory.

Magento Adobe Commerce Zero-Day Security Fix

Adobe has released a hotfix for CVE-2026-75650.

The company rates the vulnerability as Priority 1 because it is already being exploited in the wild.

Adobe recommends that affected customers apply the security fix as soon as possible.

Store administrators should use Adobe’s official security bulletin and hotfix instructions when applying the update.

How to Protect Against the Magento Adobe Commerce Zero-Day

Store owners should take several steps immediately.

Apply the Adobe Security Fix

Install the official hotfix for CVE-2026-75650.

Do not wait for the next regular maintenance cycle.

Check for Compromise

A security update may not remove an existing backdoor.

Check servers for unusual processes, cron entries, PHP files, and unexpected network connections.

Security researchers have reported suspicious processes using names such as fc-cache and chronyd.

Review Store Logs

Review application and server logs for unusual requests.

Pay special attention to unexpected activity involving GraphQL and payment-related functions.

Rotate Important Credentials

If a store may have been compromised, rotate important credentials.

This can include administrator passwords, API keys, database credentials, and other secrets.

Monitor the Store

Continue monitoring the server after applying the fix.

Attackers may attempt to return to previously compromised stores.

Why the Magento Adobe Commerce Zero-Day Is Dangerous

The vulnerability has several characteristics that increase its risk.

First, it can be exploited remotely.

Second, authentication is not required.

Third, successful exploitation can result in arbitrary code execution.

Fourth, attackers can use the access to install persistent malware.

Adobe has assigned the vulnerability a CVSS score of 10.0, the highest severity level.

For e-commerce businesses, a compromised server can create additional risks.

Attackers may target customer data, payment systems, administrator accounts, or other connected services.

What Is a Zero-Day Vulnerability?

A zero-day vulnerability is a security flaw that is unknown to the vendor or does not yet have an available fix when attackers begin exploiting it.

The term highlights the lack of preparation time available to defenders.

In the StyleSmuggler case, attackers were already exploiting the vulnerability before public disclosure. Adobe has since released an emergency fix.

To know more over Security Topic Click here https://domainera.net/ai-threat-landscape-2026-analysis/

Final Thoughts on the Magento Adobe Commerce Zero-Day

The Magento Adobe Commerce zero-day is a major security threat for online stores.

The vulnerability, tracked as CVE-2026-75650, can enable unauthenticated remote code execution. Attackers have already used the flaw to install persistent backdoors.

Adobe has released an emergency hotfix. The vulnerability carries a CVSS score of 10.0. Sansec reports that Magento and Adobe Commerce versions from 2.4.4 through 2.4.9 are affected.

Magento and Adobe Commerce administrators should apply the emergency update immediately. They should also investigate their servers for signs of compromise.

For e-commerce businesses, this is not a vulnerability to ignore. A compromised store can put customer data, payments and business operations at risk.

Last modified: September 8, 2026

Close