Adobe Commerce Zero-Day Exploited, Urgent Patch Released
A critical security vulnerability in Adobe Commerce and Magento Open Source, tracked as CVE-202675650, has been actively exploited by attackers since September 4, 2026, prompting Adobe to release an emergency hotfix. The flaw, rated with the maximum CVSS score of 10.0, allows for unauthenticated remote code execution, meaning attackers can compromise servers without needing any login credentials. Security researchers at Sansec discovered the vulnerability, which they codenamed StyleSmuggler, and observed exploitation attempts beginning on September 4. This gave attackers a significant window of opportunity before Adobe released a patch on September 8. The attack chain involves manipulating template engine properties via the GraphQL endpoint to inject malicious PHP code, which can then be executed by the platform. Observed payloads have included a Rust-based Linux backdoor and PHP web shells, according to security reports. Adobe has confirmed that CVE-202675650 has been exploited in the wild and is urging all users of Adobe Commerce and Magento Open Source to apply the VULN39341 hotfix immediately.