Adobe patches critical Magento zero-day CVE-2026-75650 used to plant backdoors
Adobe issued an emergency hotfix for a maximum-severity flaw in Magento and Adobe Commerce that attackers have exploited since at least September 4 to install a hidden backdoor. Security firm Sansec found the malware disguised its command server as an NTP time server, though compromised sites still leaked telltale fake 'Payment Transaction Failed' emails. Adobe's fix, labeled VULN-39341, covers Adobe Commerce, Commerce B2B, and Magento Open Source across multiple version branches.