Adobe fixes critical Magento zero-day exploited to backdoor servers

Summary

Adobe has released an emergency fix for a critical zero-day vulnerability, CVE-2026-75650 (StyleSmuggler), that impacts multiple versions of Magento and Adobe Commerce. This vulnerability has been actively exploited to backdoor servers.

IFF Assessment

FOE

The active exploitation of a critical zero-day vulnerability that allows attackers to backdoor servers is bad news for defenders.

Severity

10.0 Critical

Defender Context

Defenders need to prioritize patching Adobe Commerce and Magento instances immediately to mitigate the risk of server compromise. This incident highlights the ongoing threat of zero-day exploits targeting e-commerce platforms, emphasizing the importance of robust vulnerability management and timely security updates.

Read Full Story →