{"id":2734,"date":"2026-09-08T10:38:30","date_gmt":"2026-09-08T10:38:30","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2734"},"modified":"2026-09-08T10:38:30","modified_gmt":"2026-09-08T10:38:30","slug":"adobe-patches-magento-zero-day-exploited-to-deploy-rust-backdoor-and-php-web-shell","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2734","title":{"rendered":"Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 08, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg_xdakttovno7kFgFYIw5XGFGcSZibVvXYB64vih4iZpc4_WY_t7oe1X3igSPGXBa8UTkf4z4xn_GzZ_n7PmuFFvYC8Wsmb04PxYP5z-XHjZZFe_SASihwZNg1dxHXQzz8hBRo-6LhvQmwyo_MA9Kj6hrcci6ouvOX1D4f-0dNvs57M6WneQHC61yZkF_o\/s1700-nu-rw-lo-l85-e365\/magento.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe\u202fCommerce and\u202fMagento Open Source that has come under active exploitation in the wild.<\/p>\n<p>The vulnerability, now tracked as <strong>CVE-2026-75650<\/strong> (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.<\/p>\n<p>\u00abThis update resolves a critical vulnerability that could result in arbitrary code execution,\u00bb Adobe <a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb26-146.html\" target=\"_blank\">said<\/a>, adding it&#8217;s \u00abaware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>At its core, the flaw abuses Magento&#8217;s template system through PHP code injection to generate a \u00abPayment Transaction Failed Reminder\u00bb email, triggering code execution in the process.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The shortcoming affects the following versions &#8211;<\/p>\n<ul>\n<li>\n    Adobe Commerce<\/p>\n<ul>\n<li>2.4.9-2026-aug and earlier<\/li>\n<li>2.4.8-2026-aug and earlier<\/li>\n<li>2.4.7-2026-aug and earlier<\/li>\n<li>2.4.6-2026-aug and earlier<\/li>\n<li>2.4.5-2026-aug and earlier<\/li>\n<li>2.4.4-2026-aug and earlier<\/li>\n<\/ul>\n<\/li>\n<li>\n    Adobe Commerce B2B<\/p>\n<ul>\n<li>1.5.3-2026-aug and earlier<\/li>\n<li>1.5.2-2026-aug and earlier<\/li>\n<li>1.4.2-2026-aug and earlier<\/li>\n<li>1.3.4-2026-aug and earlier<\/li>\n<li>1.3.3-2026-aug and earlier<\/li>\n<\/ul>\n<\/li>\n<li>\n    Magento Open Source<\/p>\n<ul>\n<li>2.4.9-2026-aug and earlier<\/li>\n<li>2.4.8-2026-aug and earlier<\/li>\n<li>2.4.7-2026-aug and earlier<\/li>\n<li>2.4.6-2026-aug and earlier<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Patches have been released as part of a hotfix&#8217;s available for download from the following link: repo.magento[.]com\/patch\/VULN-39341-composer-patches.zip<\/p>\n<p>\u00abTo help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys,\u00bb Adobe <a href=\"https:\/\/experienceleague.adobe.com\/en\/docs\/commerce-knowledge-base\/kb\/announcements\/commerce-apsb26-146\" target=\"_blank\">said<\/a>.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The development comes days after the Dutch e-commerce security company revealed that threat actors are exploiting CVE-2026-75650 to deploy a Rust-based Linux backdoor that connects to an external server and awaits further instructions. Separately, the issue has been abused to deliver a PHP dropper on susceptible sites that writes a web shell capable of executing arbitrary PHP code.<\/p>\n<p>According to Netherlands-based Disrex, a Magento server managed by the e-commerce development platform is said to have been compromised 50 minutes after the first confirmed StyleSmuggler exploitation was reported on September 4, 2026, at 10:20 p.m. UTC.<\/p>\n<p>\u00abStyleSmuggler turns Magento&#8217;s own template-processing and dependency-injection code into an unauthenticated remote-code-execution chain,\u00bb Disrex said.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 08, 2026Vulnerability \/ Web Security Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe\u202fCommerce and\u202fMagento Open Source that has come under active exploitation in&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2735,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1135,179,229,128,793,57,1067,574,303,213,126],"class_list":["post-2734","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-adobe","tag-backdoor","tag-deploy","tag-exploited","tag-magento","tag-patches","tag-php","tag-rust","tag-shell","tag-web","tag-zeroday"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2734","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2734"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2734\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2735"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2734"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2734"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2734"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}