Skip to main content
developing→ StableCyber

Adobe Magento/Commerce Zero-Day 'StyleSmuggler' Actively Exploited for Backdoors

A max-severity zero-day vulnerability, CVE-2026-75650 'StyleSmuggler', in Adobe Magento and Adobe Commerce is confirmed to be actively exploited to deploy Linux backdoors on e-commerce servers.

Impact
5.7
Confidence
High
Evidence
3 sig · 2 src
Trajectory
→ Stable
First seen Sep 8·Updated Sep 9·Synthesized Sep 9
Export brief

Assessment

High confidence: no claims clear the two-independent-source bar yet

A max-severity zero-day vulnerability, CVE-2026-75650 'StyleSmuggler', in Adobe Magento and Adobe Commerce is confirmed to be actively exploited to deploy Linux backdoors on e-commerce servers. Adobe has released an emergency patch. The full scope of affected installations and attack chain details remain unclear.

Why it matters: Active exploitation of this vulnerability poses a significant risk of persistent compromise, data theft, and supply-chain risks for affected e-commerce platforms.

Established

  • ·Confirmed: Adobe released an emergency patch for CVE-2026-75650, a max-severity zero-day in Magento/Adobe Commerce.
  • ·Confirmed: CVE-2026-75650, dubbed 'StyleSmuggler', is actively exploited in the wild.
  • ·Confirmed: The exploitation allows remote code execution via crafted requests.
  • ·Confirmed: Exploitation leads to the deployment of a Linux backdoor on compromised servers.
  • ·Claimed: The vulnerability affects all versions of Magento and Adobe Commerce.
  • ·Unclear: The full scope of affected installations.
  • ·Unclear: The complete attack chain details.

Indicators to watch

  • Further details on the attack chain and specific threat actor attribution
  • Reports of widespread compromise or data breaches linked to StyleSmuggler
  • Updates on patch adoption rates and remaining vulnerable instances

Evidence

Confirmed · 2 independent sources · 3 signals · 2 independent sources

Central claim Adobe patches Magento zero-day StyleSmuggler exploited in the wild100% on claim

Single-source3 · 2 src · best low 49%

Topics zero-day · magento · adobe-commerce · cve-2026-75650 · remote-code-execution · active-exploitation · backdoor · linux · e-commerce · exploit

Discussion

Sign in to add a note, contribute a source, or challenge the assessment.