SecurityDeveloping

Adobe Issues Emergency Fix for Magento StyleSmuggler Zero-Day Exploited in the Wild

CVE-2026-75650 patched after attackers deployed backdoors on e-commerce sites

edit
By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
Adobe has released an emergency security patch for a critical zero-day vulnerability in Magento and Adobe Commerce, designated CVE-2026-75650 and dubbed StyleSmuggler, that has been actively exploited since at least September 4 to deploy backdoors on vulnerable e-commerce servers.

Adobe has pushed an out-of-band security update addressing CVE-2026-75650, a max-severity vulnerability in Magento and Adobe Commerce that has been exploited in the wild since at least September 4. The flaw, discovered by e-commerce security firm Sansec, allows attackers to inject PHP code through Magento's template system, leading to arbitrary code execution.

Attacks observed by Sansec have deployed a Rust-based backdoor disguised as a legitimate system process (initially as [kworker/u:8:0], later as fc-cache). The backdoor communicates with its command-and-control infrastructure using UDP packets to port 123, masking traffic as Network Time Protocol (NTP) traffic. Persistence is maintained via a cron job that repeats every 30 minutes. Sansec also reported that a second attacker using different tooling has exploited the same vulnerability to deploy a 485-byte PHP web shell that exfiltrates server data via Interactsh, an open-source security testing tool.

Affected versions include Adobe Commerce 2.4.4 through 2.4.9 (including August 2026 releases), Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.6 through 2.4.9. Adobe has assigned the update its highest priority rating and recommends immediate installation of the VULN-39341 hotfix. The vendor notes that the hotfix has only been tested against the August 2026 releases; compatibility with earlier releases is unconfirmed.

After applying the fix, administrators are advised to enable maintenance mode, suspend cron jobs, rotate all secrets (including admin passwords, API keys, and database credentials), flush the cache, restore cron execution, and disable maintenance mode. Sansec previously suggested disabling GraphQL as a temporary mitigation before the patch was available.

Indicators of compromise include an unexpected surge of "Payment Transaction Failed Reminder" emails, suspicious processes named kworker or fc-cache, and unusual cron entries or temporary files.

§

Analysis

Why This Matters

  • Businesses running Magento or Adobe Commerce are at immediate risk of website takeover and data theft if patches are not applied swiftly, as exploitation is ongoing and multiple attacker groups are involved.
  • The backdoor's use of NTP-masked traffic makes detection harder for standard network monitoring tools, increasing the window of exposure.
  • Patch deployment must be thorough: the vendor warns that credential rotation and cache flushing are essential to remove attacker access post-patch.

Background

Magento is a widely used open-source e-commerce platform owned by Adobe, powering over 160,000 websites including many high-traffic storefronts. Zero-day vulnerabilities in the platform have been targeted by cybercriminals in the past due to the direct financial value of compromised e-commerce sites. Sansec, a firm specialising in e-commerce security, identified the StyleSmuggler exploit on September 4 and disclosed it to Adobe, which deployed a fix in an unscheduled update on September 8, bypassing its typical monthly release cycle.

Key Perspectives

Adobe: Released an emergency hotfix and urged immediate installation, acknowledging active exploitation. The vendor has not commented on the attack timeline or attribution. Sansec (Security Researchers): Discovered and reported the flaw, provided detection guidance, and noted that at least two distinct attacker groups are leveraging the vulnerability with different payloads. Website Administrators: Face a race to patch and rotate credentials, with the added burden of verifying that backdoors are fully removed post-update.

What to Watch

  • Rate of patch adoption among Magento store operators — delays could lead to a wave of website compromises.
  • Emergence of additional attacker groups or follow-on ransomware/extortion campaigns targeting unpatched sites.
  • Adobe's subsequent test validation for earlier product versions and potential inclusion of the fix in the next scheduled security release.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.