www.securityweek.com 8 Sept 2026, 18:37 UTC

Adobe Patches Magento Zero Day Allowing Unauthenticated Code Execution

Adobe Patches Magento Zero Day Allowing Unauthenticated Code Execution

ADOBE has issued patches for more than 170 vulnerabilities across its product line, with urgent fixes for a critical flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. The defect, tracked as CVE-2026-75650 and rated 10/10 on the CVSS scale, is a code-injection vulnerability that allows remote code execution without authentication.

Adobe says it is aware of exploitation in the wild, and Sansec had warned over the weekend that hackers were targeting Commerce/Magento to backdoor online stores. The initial activity involved attackers injecting code that could be triggered by Magento’s standard “Payment Transaction Failed Reminder,” and Sansec’s update notes multiple threat actors deploying backdoors and web shells.

In response, Adobe released patches for eight additional Commerce vulnerabilities, including two critical privilege-escalation flaws and six high-severity security bypass and privilege-escalation bugs. Other urgent updates include CVE-2026-82004, a 10/10 OS command-injection flaw in Campaign Classic. Fresh ColdFusion updates carry priority 1 ratings, addressing CVE-2026-48273 (9.9/10) and CVE-2026-75746 (9.1/10), among seven related issues.

Adobe recommends applying all priority 1 updates within three days of release. Patches were also rolled out for 107 vulnerabilities in Experience Manager, 32 in Acrobat Reader, eight in Photoshop, three in Illustrator, and one in Animate, with fixes also issued for Photoshop Mobile. Adobe states that, aside from the Commerce/Magento zero-day, it is not aware of any of the newly resolved vulnerabilities being exploited in attacks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline