Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Adobe has issued security updates for over 170 vulnerabilities across multiple products, including an urgent patch for a critical, actively exploited zero-day in Adobe Commerce and Magento Open Source. Tracked as CVE-2026-75650 with a perfect CVSS score of 10/10, this code injection flaw enables unauthenticated remote code execution and has been leveraged by threat actors, identified by Sansec research as StyleSmuggler, to backdoor online stores through the 'Payment Transaction Failed Reminder' feature. The vendor strongly advises administrators to apply the fixes immediately and rotate all encryption keys, administrative credentials, database access details, and API tokens at their source. Additional priority one patches were also distributed for Critical Command Injection issues in Campaign Classic and ColdFusion.