Adobe has recently rolled out security patches to address more than 170 vulnerabilities in its software suite. Among these fixes, an urgent patch was provided for a critical zero-day vulnerability affecting Adobe Commerce and Magento Open Source. This flaw, identified as CVE-2026-75650, has a maximum CVSS score of 10 out of 10 and allows for remote code execution without requiring authentication.
Exploitation of the Zero-Day Vulnerability
The zero-day vulnerability, termed ‘StyleSmuggler’, came to light following warnings from cybersecurity firm Sansec. On September 4, threat actors began exploiting this flaw by injecting malicious code, triggered via Magento’s ‘Payment Transaction Failed Reminder’. This attack vector does not necessitate user involvement, making it particularly dangerous.
Sansec further disclosed that several groups have been exploiting this vulnerability to implant backdoors and web shells. As a protective measure, Adobe advises all users of Commerce/Magento to immediately apply the security patches and rotate encryption keys, along with any associated credentials such as admin passwords and API keys.
Additional Patches Released
In addition to the zero-day fix, Adobe released patches addressing eight more vulnerabilities in Commerce. These include critical privilege escalation flaws and other security bypass issues. Notably, another critical flaw, CVE-2026-82004, was patched in Campaign Classic, which posed a risk of arbitrary code execution.
The updates also cover critical vulnerabilities in ColdFusion, with two noteworthy issues receiving high priority ratings due to their potential for code execution exploits. Adobe recommends that all priority 1 updates be implemented within three days of release.
Comprehensive Software Updates
Beyond Commerce and ColdFusion, Adobe issued fixes for a wide range of its products. This includes 107 vulnerabilities in Experience Manager, 32 in Acrobat Reader, 8 in Photoshop, 3 in Illustrator, and 1 in Animate. These updates are essential to bolster security across Adobe’s software ecosystem.
Adobe has confirmed that, aside from the Commerce/Magento flaw, no other vulnerabilities addressed in this update cycle have been exploited in active attacks. Users can find further details on Adobe’s security advisories page.
These updates underscore the ongoing need for vigilance in cybersecurity practices, with Adobe’s swift response serving as a reminder of the critical importance of timely software updates.
