Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways • CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication. • Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different attack campaigns. • Adobe released Hotfix VULN-39341 on September 7, 2026, and Tenable detection plugins will be published as they become available.

·Tenable Blog
Read →
Vulnerabilities & Patches
Emerging1 src

Adobe fixes critical Magento zero-day exploited to backdoor servers

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [... ]

·BleepingComputer
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability • CVE-2026-81963 Microsoft Windows Link Following Vulnerability • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

Adobe Commerce max-severity bug comes under active attack

Online stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers. Security firm Sansec is calling the flaw StyleSmuggler because of the way attackers abused Magento’s Style properties to inject malicious code past existing safeguards. “When the attack succeeds, a backdoor background process is launched. This is a small Rust program that connects to the 99. 84. 67. 186 C2 server and waits for commands,” Sansec researchers said in a blog post , adding that the backdoor had not been weaponized at the time of writing. The flaw, tracked as CVE-2026-75650 , carries a CVSS score of 10. 0 and affects Magento and Adobe Commerce versions 2. 4. 4 through 2. 4. 9. Magento is the open-source edition of an e-commerce platform used to build and operate online stores.

·CSO Online
Read →
Vulnerabilities & Patches
Emerging1 src

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging2 srcs

CVE-2026-75650 - Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)

Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

·CISA KEV
Read →

You've reached the end of current stories for this search.