Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks

Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks

Posted on September 8, 2026 By CWS

Adobe has taken swift action by issuing security updates to mitigate a severe flaw in Adobe Commerce and Magento Open Source. This vulnerability, identified as CVE-2026-75650, was actively exploited in the wild, prompting an urgent response from Adobe to protect its users.

Details of the Critical Vulnerability

The flaw, referred to as StyleSmuggler, was discovered by Sansec on September 4, 2026. With a CVSS score of 10.0, this vulnerability allows for arbitrary code execution, posing significant risks to Adobe Commerce merchants.

The issue stems from the misuse of Magento’s template system, where PHP code injection enables unauthorized execution via a “Payment Transaction Failed Reminder” email. This flaw affects multiple versions of Adobe Commerce and Magento Open Source, requiring immediate action from users.

Versions Impacted and Available Patches

The vulnerability affects Adobe Commerce versions 2.4.9-2026-aug and earlier, and Adobe Commerce B2B versions 1.5.3-2026-aug and earlier, along with several others. Magento Open Source versions up to 2.4.6-2026-aug are also impacted.

Adobe has released a hotfix, available for download, to address this critical issue. Users are advised to apply the VULN-39341 patch and rotate encryption keys to secure their systems against potential exploits.

Exploitation and Security Implications

Following the vulnerability’s disclosure, security experts observed malicious actors employing CVE-2026-75650 to install a Rust-based Linux backdoor. This backdoor communicates with an external server, receiving commands for further exploitation.

Additionally, attackers have used the flaw to deploy a PHP dropper on vulnerable sites, enabling the execution of arbitrary PHP code through a web shell. These developments highlight the importance of applying the patch immediately to safeguard e-commerce platforms.

Reports from Netherlands-based Disrex indicate that a Magento server was compromised shortly after the first known StyleSmuggler exploitation. The rapid breach underscores the necessity for timely updates and rigorous security practices.

In conclusion, Adobe’s prompt release of security patches serves as a crucial measure to protect users from ongoing threats. Merchants and developers are urged to implement the updates to secure their systems and prevent unauthorized access.

The Hacker News Tags:Adobe, CVE-2026-75650, Magento, PHP code injection, Rust backdoor, security patch, StyleSmuggler, Vulnerability, web security, zero-day

Post navigation

Previous Post: Hackers Compromise Coder Registry for Cloud Credential Theft
Next Post: Dutch Telecom Giant Hit by Massive Data Breach via Phone Scam

Related Posts

AI Slashes Workloads for vCISOs by 68% as SMBs Demand More – New Report Reveals AI Slashes Workloads for vCISOs by 68% as SMBs Demand More – New Report Reveals The Hacker News
Turla’s STOCKSTAY Backdoor Targets Ukraine Turla’s STOCKSTAY Backdoor Targets Ukraine The Hacker News
Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and More Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and More The Hacker News
Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome The Hacker News
Supply Chain Attack Targets TanStack and AI Packages Supply Chain Attack Targets TanStack and AI Packages The Hacker News
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • U.S. Offers $10M for Iranian Cyber Chief Behind Attacks
  • Mathspace Data Breach Affects Over One Million Users
  • BengalSEO Campaign Exploits Bing for Malware and Scams
  • Dutch Telecom Giant Hit by Massive Data Breach via Phone Scam
  • Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • U.S. Offers $10M for Iranian Cyber Chief Behind Attacks
  • Mathspace Data Breach Affects Over One Million Users
  • BengalSEO Campaign Exploits Bing for Malware and Scams
  • Dutch Telecom Giant Hit by Massive Data Breach via Phone Scam
  • Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark