bleeping-computer · Crawled Sep 8, 2026

Adobe fixes critical Magento zero-day exploited to backdoor servers

1 IoCs
Read original article ↗

AI Summary

Adobe has patched a critical zero-day vulnerability, CVE-2026-75650 (StyleSmuggler), actively exploited in the wild to backdoor Magento and Adobe Commerce servers. The flaw allows arbitrary code execution, and attackers have deployed PHP web shells to exfiltrate server data. A second threat actor using different tooling has also been observed exploiting the same vulnerability. Sansec discovered the attacks, which began at least on September 4, 2026, and recommend immediate application of Adobe's hotfix and credential rotation.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain oast[.]site Details →