Attackers are exploiting a previously unknown flaw in Magento and Adobe Commerce to break into online store servers and install a hidden Linux backdoor. Sansec says the 'StyleSmuggler' zero-day affects all versions, was first seen exploited on September 4 against a fully patched target, and abuses the template system via PHP code injection to trigger remote code execution. The malware persists via cron and disguises itself as 'kworker' or 'fc-cache,' with command traffic masked as network time sync (NTP) over UDP port 123.
2026.09.09
87% relevant
This article confirms Adobe issued a hotfix for the actively exploited StyleSmuggler flaw, names it as CVE-2026-75650, notes attacks began on September 4, says all Magento and Adobe Commerce versions from 2.4.4 through 2.4.9 are affected, and adds that CISA placed it in KEV with a September 11 federal deadline.
Ionut Arghire
2026.09.08
97% relevant
This source confirms Adobe has now patched the actively exploited StyleSmuggler zero-day as CVE-2026-75650, says Adobe is aware of in-the-wild exploitation, and adds vendor remediation details including urgent patching and credential/key rotation guidance.
Bill Toulas
2026.09.08
97% relevant
This article is a direct update on the same StyleSmuggler event, adding Adobe’s emergency patch release, the CVE identifier CVE-2026-75650, affected version ranges, hotfix name VULN-39341, and Adobe’s post-compromise response guidance including secret rotation.
info@thehackernews.com (The Hacker News)
2026.09.08
97% relevant
This article appears to report the same underlying event and adds that Adobe has now issued patches for the exploited Magento/Adobe Commerce zero-day, with reporting that the attacks deployed a Rust backdoor alongside a PHP web shell.
Bill Toulas
2026.09.07
100% relevant
The article establishes a distinct new underlying event: active exploitation of a newly named Magento/Adobe Commerce zero-day, before patch release, to deploy a Linux backdoor.