Adobe Commerce Zero-day Vulnerability
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical
STABLE
What Happened
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical
Why This Matters
Publisher reporting describes a security event affecting Zero. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether Zero is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
Sep 23, 2026 11:00
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: ACTIVELY_EXPLOITED
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ it does not fetch or display exploit code.
Timeline
-
Incident first seen
Sep 08, 2026 14:43BugSkan first recorded this incident.
-
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Sep 08, 2026 14:43thehackernews.com ยท Vulnerability
-
Adobe fixes critical Magento zero-day exploited to backdoor servers
Sep 08, 2026 19:04bleepingcomputer.com ยท Vulnerability
-
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Sep 22, 2026 12:03thehackernews.com ยท Malware
-
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
Sep 23, 2026 11:00thehackernews.com ยท Data Leak
-
Latest observed development
Sep 23, 2026 11:00Most recent source or update associated with this incident.
Sources
thehackernews.com ยท Sep 08, 2026 14:43
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical
Open publisher sourcebleepingcomputer.com ยท Sep 08, 2026 19:04
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
Open publisher sourcethehackernews.com ยท Sep 22, 2026 12:03
Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in
Open publisher sourcethehackernews.com ยท Sep 23, 2026 11:00
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.