Adobe has released critical security patches for Adobe Commerce and Magento Open Source to address a maximum-severity zero-day vulnerability currently being exploited by attackers to execute arbitrary code.
Key Points
- The vulnerability, tracked as CVE-2026-75650 and codenamed StyleSmuggler, carries a maximum CVSS score of 10.0.
- Attackers are exploiting the flaw via PHP code injection in Magento’s template system to deploy Rust-based backdoors and web shells.
- Active exploitation was first identified on September 4, 2026, prompting CISA to add the flaw to its Known Exploited Vulnerabilities catalog.
- Affected users must apply the VULN-39341 patch and rotate encryption keys to secure their installations against unauthorized remote code execution.
- Adobe also issued patches for over 170 other vulnerabilities, including critical flaws in Campaign Classic and ColdFusion.