Last seen September 8, 2026

Adobe Commerce Zero-day Vulnerability

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

Why This Matters

Publisher reporting describes a security event affecting Zero. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether Zero is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Sep 08, 2026 19:04

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: ACTIVELY_EXPLOITED

Primary entities:

AdobeAdobe CommerceMagento Open SourceRemote Code ExecutionSansecZero

Authoritative Intelligence

CVE CVE-2026-75650 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

CVE-2026-75650: 4 public repository references found.

dinosn/cve-2026-75650-magento-validation-lab

Public GitHub reference

Docker lab for validating the CVE-2026-75650 Magento component-level PHP execution primitive and Adobe VULN-39341 patch.

4 stars ยท Shell

Open repository
disrex-group/stylesmuggler-adobe-patches

Public GitHub reference

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Magento, via cweagans/composer-patches. Auto-selects the patch for your Magento version.

1 stars ยท PHP

Open repository
disrex-group/stylesmuggler-adobe-patches-mageos

Public GitHub reference

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Mage-OS stores, via cweagans/composer-patches. Companion to stylesmuggler-adobe-patches (Magento).

0 stars

Open repository
jithinkrishnanrs/stylesmuggler-ioc-toolkit

Public GitHub reference

StyleSmuggler (CVE-2026-75650) IOC toolkit for Magento Open Source and Adobe Commerce. Detect compromised stores, Rust implants, PHP web shells, persistence artifacts, and known indicators of compromise.

0 stars ยท Shell

Open repository

A public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.

Timeline

  • Incident first seen
    Sep 08, 2026 14:43

    BugSkan first recorded this incident.

  • Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
    Sep 08, 2026 14:43

    thehackernews.com ยท Vulnerability

  • Adobe fixes critical Magento zero-day exploited to backdoor servers
    Sep 08, 2026 19:04

    bleepingcomputer.com ยท Vulnerability

  • Latest observed development
    Sep 08, 2026 19:04

    Most recent source or update associated with this incident.

Sources

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

thehackernews.com ยท Sep 08, 2026 14:43

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

Open publisher source
Adobe fixes critical Magento zero-day exploited to backdoor servers

bleepingcomputer.com ยท Sep 08, 2026 19:04

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence