Skip to content
Tech News
← Back to articles

Adobe fixes critical Magento zero-day exploited to backdoor servers

read original get Yubico YubiKey 5 NFC Security Key → more articles
Why This Matters

A max-severity zero-day in Adobe Commerce and Magento, dubbed StyleSmuggler, has been actively exploited since early September to install stealthy backdoors on e-commerce servers, putting online storefronts and their customers' payment data at risk. Adobe's emergency hotfix affects a wide swath of versions, and remediation goes beyond patching to full credential rotation, meaning many merchants may already be compromised.

Key Takeaways
Worth a Look

Yubico YubiKey 5 NFC Security Key — When e-commerce admin panels are under active attack, hardware-backed two-factor login is one of the strongest safeguards you can add. The YubiKey 5 NFC plugs into USB-A or taps to a phone via NFC and works with the FIDO2/WebAuthn logins many store platforms and hosting dashboards support. It's a simple, physical layer of defense for the accounts that keep your Magento or Adobe Commerce store running.

See Yubico YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.

E-commerce security company Sansec discovered that the flaw has been leveraged in attacks since at least September 4 to plant a backdoor on vulnerable websites.

The backdoor disguised its command-and-control (C2) host as a regular Network Time Protocol (NTP) server. However, it still leaves distinct signs of activity on compromised hosts, such as "Payment Transaction Failed Reminder" emails.

In an update yesterday, Adobe pushed a security fix that addresses the StyleSmuggler vulnerability in Adobe Commerce and Magento.

“This update resolves a critical vulnerability that could result in arbitrary code execution. Adobe is aware of CVE-2026-75650 being exploited in the wild,” reads the security advisory.

Adobe notes that the flaw impacts the following versions of its e-commerce products:

Adobe Commerce versions 2.4.4 through 2.4.9, including their August 2026 releases and earlier versions in each branch

Adobe Commerce B2B versions 1.3.3 through 1.5.3, including their August 2026 releases and earlier versions in each branch

Magento Open Source versions 2.4.6 through 2.4.9, including their August 2026 releases and earlier versions in each branch

The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650.

... continue reading