Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Commons breathes sigh of relief as UK finally takes a moral stance on Israeli settlements | John Crace

    September 8, 2026

    Tung Chee-hwa, Hong Kong’s first chief executive, 1937-2026

    September 8, 2026

    Rivian’s Also apologizes for delays in shipping futuristic e-bikes

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Commons breathes sigh of relief as UK finally takes a moral stance on Israeli settlements | John Crace
    • Tung Chee-hwa, Hong Kong’s first chief executive, 1937-2026
    • Rivian’s Also apologizes for delays in shipping futuristic e-bikes
    • Introducing ChatGPT Images 2.5 | OpenAI
    • Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
    • CoinCorner Launches Lloyd’s-Insured Multisig Bitcoin Vault
    • NASA Calls for Proposals to Accelerate Lunar Surface Technologies 
    • Indigenous peoples near Congo parks propose diverse solutions for the future of conservation
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day.

    Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE).

    “Adobe is aware of CVE-2026-75650 being exploited in the wild,” the company notes in its advisory. Adobe also published a KB article with details on the update.

    The security defect was patched on Monday, after cybersecurity firm Sansec warned over the weekend that hackers have been exploiting a zero-day flaw in Commerce/Magento to hack online stores.

    Attackers started exploiting the issue, dubbed StyleSmuggler, on September 4, injecting code that would be executed by triggering Magento’s standard ‘Payment Transaction Failed Reminder’, without user interaction.

    According to Sansec’s updated report, several threat actors have been targeting the vulnerability to deploy backdoors and web shells.

    Advertisement. Scroll to continue reading.

    Commerce/Magento should apply Adobe’s fixes as soon as possible and rotate their encryption keys and all credentials protected with those keys, including administrative passwords, database credentials, integration tokens, OAuth secrets, SSH and deploy keys, and API keys.

    “Rotate those at the source, not only inside Magento. Rotating the encryption key on its own does not invalidate anything an attacker already read,” Sansec notes.

    On Tuesday, Adobe released patches for eight additional Commerce vulnerabilities, including two critical-severity privilege escalation flaws and six high-severity security bypass and privilege escalation bugs.

    The company also released urgent patches for CVE-2026-82004 (CVSS score of 10/10), an OS command injection defect in Campaign Classic leading to arbitrary code execution.

    Fresh ColdFusion security updates were also assigned a priority 1 rating, as they address two critical-severity code execution security weaknesses: CVE-2026-48273 (CVSS score of 9.9/10) and CVE-2026-75746 (CVSS score of 9.1/10), and seven high- and medium-severity issues.

    Adobe recommends that all priority 1 updates be applied within three days after they were released.

    On Tuesday, Adobe also rolled out fixes for 107 vulnerabilities in Experience Manager, 32 flaws in Acrobat Reader, 8 in Photoshop, 3 in Illustrator, and 1 in Animate. Fixes were also rolled out for Photoshop Mobile.

    Adobe says it is not aware of any of the newly resolved vulnerabilities being exploited in attacks, aside from the Commerce/Magento zero-day. Additional information can be found on Adobe’s security advisories page.

    Related: SAP Patches Critical Extended Passport Processing Vulnerability

    Related: MikroTik Patches Critical Flaws Chained to Hack Routers

    Related: N-able Patches Critical Zero-Day in N-central

    Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

    Adobe commerce including Patches Vulnerabilities ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

    Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

    ChatGPT Flaw Let a Planted Prompt Send a Victim’s Gmail Data to Another Account

    Microsoft releases Windows 10 KB5122878 extended security update

    Windows 11 cumulative updates KB5124008 & KB5122880 released

    Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Commons breathes sigh of relief as UK finally takes a moral stance on Israeli settlements | John Crace

    September 8, 2026

    Tung Chee-hwa, Hong Kong’s first chief executive, 1937-2026

    September 8, 2026

    Rivian’s Also apologizes for delays in shipping futuristic e-bikes

    September 8, 2026

    Introducing ChatGPT Images 2.5 | OpenAI

    September 8, 2026
    Latest Posts

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    August 1, 2026

    AI in Formula One: Competitive advantage is all about the human in the loop

    August 1, 2026

    Pedro Sánchez hits out at EU leaders over criticism of Spain’s migrant crisis

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Commons breathes sigh of relief as UK finally takes a moral stance on Israeli settlements | John Crace

    September 8, 2026

    Tung Chee-hwa, Hong Kong’s first chief executive, 1937-2026

    September 8, 2026

    Rivian’s Also apologizes for delays in shipping futuristic e-bikes

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.