Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Manipur musician killed in Indian capital, reviving racism concerns | Racism

    September 8, 2026

    UK accuses Israeli ‘terrorists’ of ethnic cleansing in West Bank with government backing | Israel

    September 8, 2026

    Google’s Atlas of the human genome could pave the way for new treatments

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Manipur musician killed in Indian capital, reviving racism concerns | Racism
    • UK accuses Israeli ‘terrorists’ of ethnic cleansing in West Bank with government backing | Israel
    • Google’s Atlas of the human genome could pave the way for new treatments
    • Coca-Cola uses AI to improve retailer ordering in Malaysia
    • Adobe fixes critical Magento zero-day exploited to backdoor servers
    • Morning Minute: The Trenches Just Had Their Biggest Week Since TRUMP
    • ‘Plastic pollution hotspots’ spawn a public health crisis across Latin America
    • Building a Resilient Nepal by Gordon Brown
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Adobe fixes critical Magento zero-day exploited to backdoor servers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.

    E-commerce security company Sansec discovered that the flaw has been leveraged in attacks since at least September 4 to plant a backdoor on vulnerable websites.

    The backdoor disguised its command-and-control (C2) host as a regular Network Time Protocol (NTP) server. However, it still leaves distinct signs of activity on compromised hosts, such as “Payment Transaction Failed Reminder” emails.

    In an update yesterday, Adobe pushed a security fix that addresses the StyleSmuggler vulnerability in Adobe Commerce and Magento.

    “This update resolves a critical vulnerability that could result in arbitrary code execution. Adobe is aware of CVE-2026-75650 being exploited in the wild,” reads the security advisory.

    Adobe notes that the flaw impacts the following versions of its e-commerce products:

    • Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch
    • Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch
    • Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch

    The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.

    After installing the hotfix, administrators should enable maintenance mode, suspend cron jobs, and rotate all secrets, including administrator passwords, GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH keys, and API keys.

    After rotation, it is recommended to flush the cache, restore cron execution, and disable maintenance mode.

    Adobe says the hotfix has only been tested against the August 2026 releases of the affected product branches, and while it may work with other releases, compatibility with them has not been confirmed.

    In an update to its original report, Sansec says that a second attacker with unrelated tooling has been observed exploiting CVE-2026-75650 to deploy a 485-byte PHP web shell.

    The malware collects basic server details, checks whether the pub/media location is writable, and exfiltrates the data through requests to an oast.site subdomain, which is typically seen in security tests that use the Interactsh open-source tool.

    Because exploitation activity has increased, administrators are strongly advised to apply Adobe’s hotfix or mitigations as soon as possible.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Adobe Backdoor critical Exploited Fixes Magento Servers ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers build AI frameworks for widescale credential theft

    Why CISOs should focus on real AI threats, not hype

    Mathspace Data Breach Exposes Over 1 Million People

    Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

    Securing AI agents: Key controls and best practices

    220 million traveler records exposed in Vietnam-linked APIS leak

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Manipur musician killed in Indian capital, reviving racism concerns | Racism

    September 8, 2026

    UK accuses Israeli ‘terrorists’ of ethnic cleansing in West Bank with government backing | Israel

    September 8, 2026

    Google’s Atlas of the human genome could pave the way for new treatments

    September 8, 2026

    Coca-Cola uses AI to improve retailer ordering in Malaysia

    September 8, 2026
    Latest Posts

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    August 1, 2026

    AI in Formula One: Competitive advantage is all about the human in the loop

    August 1, 2026

    Pedro Sánchez hits out at EU leaders over criticism of Spain’s migrant crisis

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Manipur musician killed in Indian capital, reviving racism concerns | Racism

    September 8, 2026

    UK accuses Israeli ‘terrorists’ of ethnic cleansing in West Bank with government backing | Israel

    September 8, 2026

    Google’s Atlas of the human genome could pave the way for new treatments

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.