Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks

Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks

Posted on September 8, 2026 By CWS

Adobe has taken swift action by issuing security updates to mitigate a severe flaw in Adobe Commerce and Magento Open Source. This vulnerability, identified as CVE-2026-75650, was actively exploited in the wild, prompting an urgent response from Adobe to protect its users.

Details of the Critical Vulnerability

The flaw, referred to as StyleSmuggler, was discovered by Sansec on September 4, 2026. With a CVSS score of 10.0, this vulnerability allows for arbitrary code execution, posing significant risks to Adobe Commerce merchants.

The issue stems from the misuse of Magento’s template system, where PHP code injection enables unauthorized execution via a “Payment Transaction Failed Reminder” email. This flaw affects multiple versions of Adobe Commerce and Magento Open Source, requiring immediate action from users.

Versions Impacted and Available Patches

The vulnerability affects Adobe Commerce versions 2.4.9-2026-aug and earlier, and Adobe Commerce B2B versions 1.5.3-2026-aug and earlier, along with several others. Magento Open Source versions up to 2.4.6-2026-aug are also impacted.

Adobe has released a hotfix, available for download, to address this critical issue. Users are advised to apply the VULN-39341 patch and rotate encryption keys to secure their systems against potential exploits.

Exploitation and Security Implications

Following the vulnerability’s disclosure, security experts observed malicious actors employing CVE-2026-75650 to install a Rust-based Linux backdoor. This backdoor communicates with an external server, receiving commands for further exploitation.

Additionally, attackers have used the flaw to deploy a PHP dropper on vulnerable sites, enabling the execution of arbitrary PHP code through a web shell. These developments highlight the importance of applying the patch immediately to safeguard e-commerce platforms.

Reports from Netherlands-based Disrex indicate that a Magento server was compromised shortly after the first known StyleSmuggler exploitation. The rapid breach underscores the necessity for timely updates and rigorous security practices.

In conclusion, Adobe’s prompt release of security patches serves as a crucial measure to protect users from ongoing threats. Merchants and developers are urged to implement the updates to secure their systems and prevent unauthorized access.

The Hacker News Tags:Adobe, CVE-2026-75650, Magento, PHP code injection, Rust backdoor, security patch, StyleSmuggler, Vulnerability, web security, zero-day

Post navigation

Previous Post: Hackers Compromise Coder Registry for Cloud Credential Theft
Next Post: Dutch Telecom Giant Hit by Massive Data Breach via Phone Scam

Related Posts

Announcing Cybersecurity Stars Awards 2026 Announcing Cybersecurity Stars Awards 2026 The Hacker News
North Korea-Linked Hackers Steal .02 Billion in 2025, Leading Global Crypto Theft North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft The Hacker News
Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia The Hacker News
Hacker Server Leak Unveils Massive WordPress Breach Hacker Server Leak Unveils Massive WordPress Breach The Hacker News
Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps Server Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps Server The Hacker News
Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dutch Telecom Giant Hit by Massive Data Breach via Phone Scam
  • Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks
  • Hackers Compromise Coder Registry for Cloud Credential Theft
  • Grindr Settles U.K. Data Sharing Claims for £26 Million
  • Npm Worm Returns After 111 Days, Evades Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dutch Telecom Giant Hit by Massive Data Breach via Phone Scam
  • Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks
  • Hackers Compromise Coder Registry for Cloud Credential Theft
  • Grindr Settles U.K. Data Sharing Claims for £26 Million
  • Npm Worm Returns After 111 Days, Evades Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark