Threat Intelligence

Critical Magento Flaw Under Active Attack: Patch Now to Block Backdoor Installs

The Hacker News · 8 Sept 2026
Key Takeaway If your business runs Adobe Commerce or Magento Open Source, apply Adobe's emergency patch immediately and rotate encryption keys, since delays leave you exposed to fast-moving automated attacks.

Adobe has issued urgent security patches for a critical flaw in Adobe Commerce and Magento Open Source, tracked as CVE-2026-75650 and rated the highest possible severity score of 10.0. Researchers at Sansec, who named the flaw StyleSmuggler, discovered it being exploited in the wild from September 4, 2026. Adobe has confirmed the vulnerability is being actively used to target Adobe Commerce merchants.

The flaw works by abusing Magento's template system, allowing attackers to inject malicious code through an automatically generated email notification, which then triggers code execution on the server. Security researchers report that attackers have used this weakness to install a Rust-based backdoor on Linux systems that connects to an external server for further instructions, as well as a PHP web shell that lets attackers run arbitrary code on compromised sites. One security firm noted that a managed Magento server was compromised just 50 minutes after the first confirmed exploitation attempt was detected.

Adobe has released a hotfix patch and is urging affected merchants to apply it immediately and rotate their encryption keys as part of the remediation process, since simply patching the flaw may not remove access already gained by attackers.

Magento Adobe Commerce zero-day e-commerce security patch management

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.