Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. E-commerce security company Sansec discovered that the flaw has been leveraged in attacks since at least September 4 to plant a backdoor on vulnerable websites. The backdoor disguised its command-and-control (C2) host as a regular Network Time Protocol (NTP) server. However, it still leaves distinct signs of activity on compromised hosts, such as "Payment Transaction Failed Reminder" emails. In an update yesterday, Adobe pushed a security fix that addresses the StyleSmuggler vulnerability in Adobe Commerce and Magento. “This update resolves a critical vulnerability that could result in arbitrary code execution. Adobe is aware of CVE-2026-75650 being exploited in the wild,” reads the security advisory. Adobe notes that the flaw impacts the following versions of its e-commerce products: The vendor assigned the highest priority rating for the update and recommends installing the VULN-39341 hotfix immediately to address CVE-2026-75650. After installing the hotfix, administrators should enable maintenance mode, suspend cron jobs, and rotate all secrets, including administrator passwords, GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH keys, and API keys. After rotation, it is recommended to flush the cache, restore cron execu...
Adobe fixes critical Magento zero-day exploited to backdoor servers
Affected Software
Frequently Asked Questions
Which products are affected by CVE-2026-75650?
The vulnerability affects multiple versions of Adobe Commerce and Magento. The article does not include the specific affected version list.
What should administrators do to address the vulnerability?
Adobe recommends installing the VULN-39341 hotfix immediately. Adobe assigned the update its highest priority rating because the flaw can result in arbitrary code execution and is being exploited in the wild.
What evidence may indicate a server was compromised?
Sansec reported that attackers used the flaw to plant a backdoor and disguised its command-and-control host as a normal NTP server. Compromised hosts may also show “Payment Transaction Failed Reminder” emails.
Is exploitation of this vulnerability confirmed?
Yes. Adobe states it is aware of CVE-2026-75650 being exploited in the wild, and Sansec says attacks have used it since at least September 4. The vulnerability is also listed as exploited in the supplied article metadata.