Tech News
← Home  ·  All topics

Adobe Commerce

2 GoKawiil briefs on this topic

Adobe patches critical Magento zero-day CVE-2026-75650 used to plant backdoors

Adobe issued an emergency hotfix for a maximum-severity flaw in Magento and Adobe Commerce that attackers have exploited since at least September 4 to install a hidden backdoor. Security firm Sansec found the malware disguised its command server as an NTP time server, though compromised sites still leaked telltale fake 'Payment Transaction Failed' emails. Adobe's fix, labeled VULN-39341, covers Adobe Commerce, Commerce B2B, and Magento Open Source across multiple version branches.

Unpatched Magento flaw 'StyleSmuggler' used to install Linux backdoor on e-commerce sites

Security firm Sansec has detected active exploitation of an unpatched vulnerability, dubbed StyleSmuggler, affecting all versions of Magento and Adobe Commerce. Attackers inject PHP code through the platform's template system by triggering a fake failed-payment email, which then installs a Rust-based backdoor disguised as a legitimate Linux process and sets up a cron job for persistence. Adobe has confirmed it is working on a patch but has not given a release date.