Critical Magento Flaw Under Active Attack: Patch Now to Block Backdoor Installs
Adobe has issued urgent security patches for a critical flaw in Adobe Commerce and Magento Open Source, tracked as CVE-2026-75650 and rated the highest possible severity score of 10.0. Researchers at Sansec, who named the flaw StyleSmuggler, discovered it being exploited in the wild from September 4, 2026. Adobe has confirmed the vulnerability is being actively used to target Adobe Commerce merchants.
The flaw works by abusing Magento's template system, allowing attackers to inject malicious code through an automatically generated email notification, which then triggers code execution on the server. Security researchers report that attackers have used this weakness to install a Rust-based backdoor on Linux systems that connects to an external server for further instructions, as well as a PHP web shell that lets attackers run arbitrary code on compromised sites. One security firm noted that a managed Magento server was compromised just 50 minutes after the first confirmed exploitation attempt was detected.
Adobe has released a hotfix patch and is urging affected merchants to apply it immediately and rotate their encryption keys as part of the remediation process, since simply patching the flaw may not remove access already gained by attackers.