Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Summary

Adobe has released patches for a critical zero-day vulnerability in Adobe Commerce and Magento Open Source. This vulnerability, codenamed StyleSmuggler, has been actively exploited since September 4, 2026, to deploy a Rust backdoor and PHP web shell.

IFF Assessment

FOE

The exploitation of a critical zero-day vulnerability in Adobe Commerce and Magento Open Source leading to the deployment of backdoors and web shells represents a significant threat to organizations relying on these platforms.

Severity

10.0 Critical

Defender Context

This zero-day highlights the immediate need for organizations using Adobe Commerce and Magento Open Source to apply the latest security patches. Defenders should be vigilant for signs of compromise, including unusual network activity or the presence of unknown files, as attackers are actively exploiting this flaw.

Read Full Story →