Close Menu
NCIJ Network NCIJ Network
    What's Hot

    US escalates ahead of UK trade sanctions on Israeli settlements – POLITICO

    September 8, 2026

    Majority of Tory and Reform voters do not back cuts to disability benefits, survey finds | Disability

    September 8, 2026

    UK commits £100m to bolster Ukraine’s air defences over winter | Foreign policy

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US escalates ahead of UK trade sanctions on Israeli settlements – POLITICO
    • Majority of Tory and Reform voters do not back cuts to disability benefits, survey finds | Disability
    • UK commits £100m to bolster Ukraine’s air defences over winter | Foreign policy
    • Xiaomi’s wide foldable promises more power than Samsung’s
    • Google WeatherNext 3 pushes AI weather forecasting into energy markets
    • Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
    • Hunter Biden’s LAPTOP memecoin: launch and tokenomics
    • The Cost of Keeping Cool: Georgia Power Customers Struggle With Summer Bills
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 08, 2026Vulnerability / Web Security

    Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.

    The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.

    “This update resolves a critical vulnerability that could result in arbitrary code execution,” Adobe said, adding it’s “aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants.”

    Cybersecurity

    At its core, the flaw abuses Magento’s template system through PHP code injection to generate a “Payment Transaction Failed Reminder” email, triggering code execution in the process.

    The shortcoming affects the following versions –

    • Adobe Commerce

      • 2.4.9-2026-aug and earlier
      • 2.4.8-2026-aug and earlier
      • 2.4.7-2026-aug and earlier
      • 2.4.6-2026-aug and earlier
      • 2.4.5-2026-aug and earlier
      • 2.4.4-2026-aug and earlier
    • Adobe Commerce B2B

      • 1.5.3-2026-aug and earlier
      • 1.5.2-2026-aug and earlier
      • 1.4.2-2026-aug and earlier
      • 1.3.4-2026-aug and earlier
      • 1.3.3-2026-aug and earlier
    • Magento Open Source

      • 2.4.9-2026-aug and earlier
      • 2.4.8-2026-aug and earlier
      • 2.4.7-2026-aug and earlier
      • 2.4.6-2026-aug and earlier

    Patches have been released as part of a hotfix’s available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip

    “To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys,” Adobe said.

    Cybersecurity

    The development comes days after the Dutch e-commerce security company revealed that threat actors are exploiting CVE-2026-75650 to deploy a Rust-based Linux backdoor that connects to an external server and awaits further instructions. Separately, the issue has been abused to deliver a PHP dropper on susceptible sites that writes a web shell capable of executing arbitrary PHP code.

    According to Netherlands-based Disrex, a Magento server managed by the e-commerce development platform is said to have been compromised 50 minutes after the first confirmed StyleSmuggler exploitation was reported on September 4, 2026, at 10:20 p.m. UTC.

    “StyleSmuggler turns Magento’s own template-processing and dependency-injection code into an unauthenticated remote-code-execution chain,” Disrex said.

    Adobe Backdoor Deploy Exploited Magento Patches PHP Rust Shell Web ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Securing AI agents: Key controls and best practices

    220 million traveler records exposed in Vietnam-linked APIS leak

    Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    OpenAI Agents Hijack Another Victim Website

    N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US escalates ahead of UK trade sanctions on Israeli settlements – POLITICO

    September 8, 2026

    Majority of Tory and Reform voters do not back cuts to disability benefits, survey finds | Disability

    September 8, 2026

    UK commits £100m to bolster Ukraine’s air defences over winter | Foreign policy

    September 8, 2026

    Xiaomi’s wide foldable promises more power than Samsung’s

    September 8, 2026
    Latest Posts

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US escalates ahead of UK trade sanctions on Israeli settlements – POLITICO

    September 8, 2026

    Majority of Tory and Reform voters do not back cuts to disability benefits, survey finds | Disability

    September 8, 2026

    UK commits £100m to bolster Ukraine’s air defences over winter | Foreign policy

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.