Summary
- CVE-2026-75650 carries a CVSS score of 10.0 and affects Adobe Commerce and Magento Open Source.
- Active exploitation was detected by Sansec from 4 September 2026, ahead of Adobe’s patch release.
- Sansec has named the campaign StyleSmuggler; confirmed payloads include a Rust-based backdoor and a PHP web shell.
- Adobe has released patches and organisations running affected versions should prioritise remediation immediately.
- No corroborating sources are available at this time beyond the primary reporting.
What Happened
Adobe released security updates on Monday to address a critical vulnerability in Adobe Commerce and Magento Open Source. The flaw, assigned CVE-2026-75650 with a CVSS score of 10.0, was already being exploited before patches became available, placing it firmly in the zero-day category.
Who Found It and When
Security firm Sansec identified active exploitation of the vulnerability beginning 4 September 2026. Sansec has labelled the campaign StyleSmuggler. The source material does not detail how Sansec discovered the activity or what affected organisations were targeted.
What the Attackers Deployed
According to the source reporting, attackers exploiting CVE-2026-75650 have deployed two distinct malicious components: a backdoor written in Rust and a PHP web shell. Rust-based malware is relatively uncommon in e-commerce attack chains and can complicate detection for teams relying on signature-based tooling tuned to more traditional payloads. A PHP web shell, by contrast, is a well-understood persistence mechanism that gives attackers ongoing remote access to compromised servers.
What Is Known About the Vulnerability Itself
The source material describes the issue as a critical vulnerability resolved by Adobe’s update, but does not provide a detailed technical breakdown of the underlying weakness — whether it is an authentication bypass, a remote code execution flaw, or something else entirely. A CVSS score of 10.0 indicates the highest possible severity rating under that framework, typically reflecting unauthenticated remote exploitability with no required user interaction. CISOs should consult Adobe’s official security bulletin for the full technical profile.
Scope and Exposure
Adobe Commerce and Magento Open Source underpin a significant portion of global e-commerce infrastructure, including many mid-market and enterprise retail environments. Organisations running unpatched instances — including those exposed to the internet through standard storefront or administration interfaces — should treat their exposure as active until patched. The source material does not specify which versions are affected beyond the platform names, so version-level scoping will require reference to Adobe’s advisory.
Limitations of Current Reporting
No corroborating sources were available at the time of writing. The attribution of the campaign, the full scope of victim organisations, and the precise technical mechanism of exploitation are not described in the source material. This briefing reflects only what has been reported and confirmed through that single source.
Why it matters
A CVSS 10.0 zero-day exploited before a patch was available represents a worst-case scenario for any organisation running Adobe Commerce or Magento Open Source. The deployment of both a Rust backdoor and a PHP web shell suggests attackers are pursuing durable persistence, not opportunistic access. For CISOs in retail, e-commerce, or any sector running these platforms, the priority question is straightforward: are your instances patched, and if exploitation occurred before patching, is there evidence of compromise? The combination of an unfamiliar Rust payload with a conventional PHP shell means detection needs to cover both layers.
What to do now
- Apply Adobe’s patches for CVE-2026-75650 to all Adobe Commerce and Magento Open Source instances without delay.
- Review Adobe’s official security bulletin to confirm which specific versions are affected and verify your environment’s patch status.
- Conduct threat hunting across affected systems for indicators associated with the StyleSmuggler campaign, including evidence of Rust-based executables and PHP web shells introduced after 4 September 2026.
- Review web server and application logs from 4 September 2026 onwards for anomalous activity that may indicate exploitation occurred prior to patching.
- If compromise is suspected, isolate affected instances and conduct a formal incident response process before returning them to production.
