Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe has issued emergency patches for a critical remote code execution vulnerability affecting Adobe Commerce and Magento Open Source, confirmed to be under active attack. Tracked as CVE-2026-75650 with a maximum CVSS score of 10.0, this flaw allows attackers to execute arbitrary code by abusing the platform's template processing mechanisms.
Threat actors have already leveraged the zero-day to install persistent threats, including a custom Rust-based Linux backdoor and PHP web shells on compromised stores. To mitigate the risk, administrators must immediately apply the VULN-39341 hotfix and rotate all encryption keys across vulnerable versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source.