A maximum-severity zero-day in Adobe Commerce and Magento, tracked as CVE-2026-75650 and nicknamed StyleSmuggler, has been used since at least 4 September to plant persistent server backdoors. UK retailers running affected builds should treat Adobe's emergency hotfix and incident response planning as immediate priorities, not routine patch-cycle items.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Silent zero-day exploitation… | 0 | 1 |
| Second attacker deploys web… | 1 | 1 |
| Adobe emergency hotfix… | 2 | 1 |
What Adobe confirmed
Adobe has pushed out a rush patch for CVE-2026-75650, a top-severity flaw carrying a full CVSS score of 10.0, after Sansec reported real-world exploitation beginning on 4 September, including backdoor deployment on Magento and Adobe Commerce servers. The company's advisory confirms it is aware of ongoing exploitation and marked the update as top priority, releasing it under the identifier hotfix VULN-39341.
Why StyleSmuggler is unusually dangerous
Exploiting the bug lets attackers run arbitrary code, and Sansec's investigation found the resulting implant masks its command-and-control channel to look like a routine Network Time Protocol server. One observed Rust backdoor variant contacts a host at 99.84.67.186. Sansec and other researchers describe two Rust backdoor variants, named fc-cache and chronyd, and flag telltale compromise indicators including stray "Payment Transaction Failed Reminder" emails going out from breached stores.
A separate, unconnected threat actor has also been caught abusing the same bug to plant a far smaller 485-byte PHP web shell inside the product image cache; this tool gathers basic server information and sends it out through an oast.site subdomain, a signature associated with the Interactsh open-source testing framework. Two independent campaigns exploiting the same zero-day within days of each other is a strong signal that the flaw is now widely known and being probed at scale, which raises the stakes for anyone still running unpatched infrastructure.
Who is exposed
According to Adobe, the vulnerable versions span Adobe Commerce 2.4.4 to 2.4.9, Adobe Commerce B2B 1.3.3 to 1.5.3, and Magento Open Source 2.4.6 to 2.4.9, and include the August 2026 releases and earlier versions in each branch. Sansec reproduced the unauthenticated exploit chain on clean Magento Open Source installs of 2.4.7, 2.4.8 and 2.4.9, and its first confirmed victim was running 2.4.6-p15 with July and August 2026 security updates already applied — showing that being on the latest security updates for that branch did not prevent exploitation of this zero-day.
Notably, Adobe confirms it has validated the hotfix solely on the August 2026 builds within each branch. Buyers on older or heavily customised builds should assume compatibility is unconfirmed and plan validation testing rather than deploying blind into production.

Immediate response steps for UK operators
Adobe recommends following its post-hotfix checklist step by step: switch on maintenance mode, pause cron jobs, then cycle every category of credential the platform relies on — admin passwords, GraphQL integration tokens, OAuth client secrets, payment gateway API keys, database logins, SSH keys and API keys — before clearing the cache, resuming cron and switching maintenance mode back off. Sansec has separately recommended its eComscan tool for detecting the implant, and noted that its Shield product's 1.9.7 update terminates the malicious process; interim mitigations while patching is scheduled included temporarily disabling GraphQL.
For teams without dedicated in-house capacity, this is exactly the scenario where structured vulnerability management and patching processes and a clear incident response planning playbook pay for themselves — the difference between a contained hotfix rollout and a prolonged forensic clean-up on customer-facing infrastructure.
Part of a busy year for Commerce and Magento
This is not an isolated event. Adobe disclosed CVE-2026-71362, an Incorrect Authorization flaw in Adobe Commerce, in August 2026, and around the same time reported attacks hijacking customer accounts on Commerce and Magento. Adobe also shipped fixes for additional critical Adobe Commerce and Magento issues in July 2026. For retailers running self-hosted storefronts, that cadence argues for treating platform patching as continuous operational discipline rather than a quarterly task, supported by understanding patch management and enforced through zero trust segmentation between the storefront, admin panel and payment integrations.
Because this class of attack results in server-side persistence rather than a simple account compromise, recovery planning matters as much as prevention. Verified, tested restore points via immutable backups for cyber resilience reduce the temptation to pay or rebuild from a potentially re-infected snapshot, and managed detection & response coverage helps catch the anomalous NTP-style beaconing or web shell traffic that a WAF alone may miss.
What this means for procurement and risk owners
Retail and e-commerce infrastructure buyers should treat this incident as a prompt to re-check where Magento or Adobe Commerce sits in their estate, whether it's on a supported branch, and whether credential rotation and log review have actually happened rather than been assumed. Given the max CVSS 10.0 rating and confirmed active exploitation, this sits firmly in the category that warrants board-level visibility, not just a ticket in the platform team's backlog. Organisations without mature internal security operations should assess whether comprehensive cybersecurity solutions covering patch validation, monitoring and response are already in place before the next zero-day lands.
- 01BleepingComputer — Adobe fixes critical Magento zero-day exploited to backdoor servers · 8 September 2026
- 02BleepingComputer — Magento StyleSmuggler zero-day exploited to deploy Linux backdoor · 8 September 2026
- 03BleepingComputer — Hackers exploit critical Adobe Commerce flaw to hijack customer accounts · 1 August 2026
- 04The Hacker News — Unpatched Magento and Adobe Commerce · 8 September 2026
- 05The Hacker News — Adobe patches Magento zero-day · 8 September 2026
- 06bleepingcomputer.com
- 07bleepingcomputer.com
- 08bleepingcomputer.com
