thehackernews.com 8 Sept 2026, 09:13 UTC

Adobe Patches Actively Exploited Magento Flaw Enabling Server Takeover

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ADOBE has released security patches for Adobe Commerce and Magento Open Source to fix a critical, actively exploited vulnerability tracked as CVE-2026-75650 (CVSS 10.0), codenamed StyleSmuggler by Sansec. Exploitation in the wild began around 4 September 2026. Adobe states the flaw could allow arbitrary code execution and that CVE-2026-75650 has been used against affected Adobe Commerce merchants.

The vulnerability stems from PHP code injection via Magento’s template system, which can be triggered to generate a “Payment Transaction Failed Reminder” email and, in the process, execute remote code on the server.

Affected products and versions include: Adobe Commerce 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier, 2.4.5-2026-aug and earlier, 2.4.4-2026-aug and earlier; Adobe Commerce B2B 1.5.3-2026-aug and earlier, 1.5.2-2026-aug and earlier, 1.4.2-2026-aug and earlier, 1.3.4-2026-aug and earlier, 1.3.3-2026-aug and earlier; Magento Open Source 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier.

Adobe instructs applying the VULN-39341 patch (appropriate to your version) and rotating encryption keys. Evidence from the Dutch security firm Disrex notes a Magento server being compromised within 50 minutes of the first confirmed StyleSmuggler exploitation on 4 September 2026, and prior reporting cited threat actors deploying a Rust-based Linux backdoor and a PHP dropper delivering a web shell. The patch is available via repo.magento[.]com/patch/VULN-39341-composer-patches[.]zip.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline