Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has issued an emergency update to address CVE-2026-75650, a critical zero-day flaw in Magento and Adobe Commerce that is currently being leveraged to deploy backdoors on compromised servers. E-commerce security firm Sansec identified active exploitation of this vulnerability, referred to as StyleSmuggler, starting in early September, where attackers used it to install persistent access mechanisms disguised as NTP servers. Affected products include Adobe Commerce versions 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.6 through 2.4.9.
The vendor has released the VULN-39341 hotfix to resolve this arbitrary code execution issue. Administrators are urged to apply the patch immediately and subsequently rotate all administrative credentials, API keys, and secrets to mitigate potential compromise.