Search
Find merged stories by title or summary.
Adobe Patches Critical Flaws in Connect, AEM Forms
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek .
StyleSmuggler 0-Day Exploited to Hack Adobe Commerce and Magento Stores - Hackread
StyleSmuggler 0-Day Exploited to Hack Adobe Commerce and Magento Stores Hackread
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability • CVE-2026-81963 Microsoft Windows Link Following Vulnerability • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability CVE-2026-75650 (CVSS score of 10. 0) is an Adobe Commerce and Magento improper neutralization of special elements in a template engine vulnerability that can lead to unauthenticated remote code execution.
ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3. 3. The following CVEs are assigned: CVE-2026-80160.
ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-81985.
ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-81990.
ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-81989.
ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3. 3. The following CVEs are assigned: CVE-2026-79910.
ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-81975.
ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3. 3. The following CVEs are assigned: CVE-2026-81984.
ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3. 3. The following CVEs are assigned: CVE-2026-81978.
ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-80161.
ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3. 3. The following CVEs are assigned: CVE-2026-81977.
ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-81988.
ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-81981.
ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-81973.
ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-75771.
ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-81976.
ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-81986.
ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-79909.
ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-75863.
ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-75862.
ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3. 3. The following CVEs are assigned: CVE-2026-81991.
ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3. 3. The following CVEs are assigned: CVE-2026-80162.
ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-81987.
Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices. Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update. Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints. Fake browser makes phishing harder to spot BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript.
InfoSec News Nuggets – 09/08/2026
InfoSec News Nuggets – 09/08/2026 Adobe Fixes Critical Magento Zero-Day Exploited to Backdoor Servers Adobe released an emergency out-of-cycle patch for CVE-2026-75650, a maximum-severity zero-day dubbed StyleSmuggler affecting Magento Open Source and Adobe Commerce, after e-commerce security firm Sansec discovered attackers exploiting it since September 4 to plant backdoors on vulnerable stores. The flaw abuses Magento’s template-processing system to inject and execute malicious PHP code, and Sansec confirmed the technique compromised at least one store that was fully current on every prior security update — meaning normal patching discipline alone wasn’t enough to prevent infection.
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek .
The September 2026 Security Update Review
Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extend break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our YouTube channel. It should be posted within a couple of hours after the release. Adobe Patches for September 2026 For the first part of the August release, Adobe released 10 bulletins addressing 172 unique CVEs in Adobe ColdFusion, Acrobat Reader, Commerce (two bulletins), Campaign Classic, Experience Manager, Photoshop, Illustrator, Animate, and Adobe Photoshop Mobile.
StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways • CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication. • Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different attack campaigns. • Adobe released Hotfix VULN-39341 on September 7, 2026, and Tenable detection plugins will be published as they become available.
Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [... ]
Adobe Commerce max-severity bug comes under active attack
Online stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers. Security firm Sansec is calling the flaw StyleSmuggler because of the way attackers abused Magento’s Style properties to inject malicious code past existing safeguards. “When the attack succeeds, a backdoor background process is launched. This is a small Rust program that connects to the 99. 84. 67. 186 C2 server and waits for commands,” Sansec researchers said in a blog post , adding that the backdoor had not been weaponized at the time of writing. The flaw, tracked as CVE-2026-75650 , carries a CVSS score of 10. 0 and affects Magento and Adobe Commerce versions 2. 4. 4 through 2. 4. 9. Magento is the open-source edition of an e-commerce platform used to build and operate online stores.
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical
Hackers hit Magento/Adobe Commerce stores using a perfect zero-day exploit - Cybernews
Hackers hit Magento/Adobe Commerce stores using a perfect zero-day exploit Cybernews
CVE-2026-75650 - Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
StyleSmuggler: The Magento Zero-Day Behind New Store Attacks
StyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched. A new zero-day flaw, dubbed StyleSmuggler, in Magento and Adobe Commerce is under active attack, giving unauthenticated attackers a path to run code on vulnerable online stores. Sansec researchers say it affects current Magento Open Source releases, including 2. 4. 7, 2. 4. 8 and 2. 4. 9. According to the experts, exploitation began on September 4. “Sansec discovered StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. All current versions are affected, including 2. 4. 9.” reads the report published by Sansec. “Attacks started September 4th. Sansec is rolling out emergency mitigation.” This is not a routine patch-cycle problem.
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [... ]
StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited
StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited Attackers are actively exploiting an unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce that allows unauthenticated remote code execution and persistent backdoor installation. Dutch e-commerce security firm Sansec discovered the flaw, named StyleSmuggler , and published an early advisory on September 5, 2026, warning that online stores were already being compromised. As of September 7, 2026, Adobe has not issued a CVE identifier, an advisory, a patch, or a workaround. What Is StyleSmuggler? StyleSmuggler is an unauthenticated remote code execution vulnerability affecting Magento Open Source and Adobe Commerce. The flaw allows an attacker to execute arbitrary code on a store’s server without any authentication, then install a persistent backdoor.
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek .
Hackers Exploit StyleSmuggler Magento and Adobe Commerce Zero-Day for Unauthenticated RCE
A newly disclosed actively exploited zero-day vulnerability in Magento and Adobe Commerce allows unauthenticated attackers to execute code remotely on affected e-commerce stores. The flaw, named StyleSmuggler, was discovered by Sansec’s Forensics Team, which warned that exploitation began on September 4. The issue is currently unpatched and impacts all supported Magento and Adobe Commerce versions, including Magento Open Source 2. 4. 9. Sansec reproduced the complete unauthenticated attack chain on clean Magento Open Source installations of 2. 4. 7, 2. 4. 8, and 2. 4. 9. Hackers Exploit StyleSmuggler Magento and Adobe Commerce Zero-Day Sansec also identified a victim running Magento 2. 4. 6-p15 with July and August 2026 security patches installed, despite the system reporting a clean security:patch-status result.
