Adobe fixes critical Magento zero-day exploited to backdoor servers

ExploitedCriticalBleepingComputer · Bill Toulas·

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what NexaPulse adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

At a glance

Severity
Criticalfrom category and source signals; no CVSS referenced
Exploitation
Confirmed — 1 of 1 referenced vulnerability is on the CISA Known Exploited Vulnerabilities catalogue
Vulnerabilities
CVE-2026-75650
Vendors & products
Adobe
Threat actors & malware
None named
Coverage
1 outlet· first seen 2026-09-08 13:34 UTC
Priority
71/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.

Vulnerabilities referenced

  • CVE-2026-75650Exploited· due 2026-09-11

    Adobe Commerce and Magento

    Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

    Added to KEV 2026-09-08

    Full record →

Coverage

One outlet has carried this so far.

  1. BleepingComputerEstablished SourceFirst reported

    2026-09-08 13:34 UTC

Related stories