Adobe Commerce max-severity bug comes under active attack

Summary

A critical zero-day vulnerability, dubbed StyleSmuggler and identified as CVE-2026-75650, is being actively exploited in Adobe Commerce and Magento Open Source platforms. This flaw allows unauthenticated attackers to execute code on vulnerable servers, leading to the deployment of backdoors. Adobe has released an emergency hotfix, but organizations are warned that patching may not be sufficient for already compromised systems.

IFF Assessment

FOE

This vulnerability allows attackers to gain unauthorized code execution, posing a significant risk to e-commerce platforms and their sensitive data.

Severity

10.0 Critical

Defender Context

This zero-day vulnerability in Adobe Commerce and Magento presents an immediate and severe threat to e-commerce businesses. Defenders must prioritize applying the emergency hotfix and should also conduct thorough investigations for signs of compromise, as exploitation occurred before a patch was available. The use of a backdoor that connects to a C2 server highlights the need for robust network monitoring and threat hunting capabilities.

Read Full Story →