Cyber Resilience
← All news
Corroborated

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Our takeAdobe fixed CVE-2026-75650, the StyleSmuggler zero-day actively exploited in Magento/Adobe Commerce to drop a Rust backdoor and PHP web shell. Patch immediately if you run self-hosted instances (some enterprises and smaller shops alike).
Sources (3)
What this means for you — Security leader:Patch Adobe Commerce and Magento Open Source to the latest build immediately if you self-host; the CVE-2026-75650 zero-day is under active exploitation.
What this means for you — Lean IT orgs:If you run your own Magento or Adobe Commerce store, apply the patch today. Most lean teams use hosted platforms and can ignore this one.
What this means for you — MSP:Check every client running self-hosted Adobe Commerce or Magento Open Source and push the update now; the zero-day is already being exploited in the wild.
What this means for you — Researcher:Sansec's StyleSmuggler zero-day (CVE-2026-75650) in Adobe Commerce/Magento is actively exploited to deploy a Rust backdoor and PHP web shell. Patch immediately if you run self-hosted instances.