Published Tuesday, September 08, 2026 at 05:18 AM PT

BLUF: Adobe has released patches for a critical zero-day vulnerability in Magento and Adobe Commerce actively exploited to install Rust backdoors and PHP web shells on e-commerce platforms. All affected systems require immediate patching.
DETAILS
- Vulnerability: Zero-day in Adobe Commerce and Magento Open Source (referenced as “StyleSmuggler” in multiple security reports); enables unauthenticated remote code execution
- Active exploitation confirmed: Attackers are successfully compromising unpatched Magento instances in the wild; backdoors and web shells already deployed on compromised stores
- Payload: Rust-based backdoors and Linux backdoors paired with PHP web shells for persistent access and command execution
- Patch status: Adobe has released security updates; patch versions and CVE identifier not specified in available sources but patch availability confirmed
- Attack scope: Targets publicly exposed Magento/Adobe Commerce installations; e-commerce platforms with vulnerable deployments are primary victims
IMPACT
- Affected systems: All Adobe Commerce and Magento Open Source installations that have not applied the available patches
- Threat to data: Compromised stores face payment card theft, customer credential harvesting, malware distribution, and inventory manipulation
- Scale: Multiple independent security vendors reporting active exploitation; suggests widespread attacker activity
RECOMMENDED ACTIONS
- Immediate: Identify all Magento and Adobe Commerce instances in your environment; apply available Adobe security patches without delay
- Detection: Hunt for PHP web shells in web root directories; monitor process logs for unusual Rust/Linux backdoor execution
- Access review: Audit authentication logs for exploitation attempts; check for suspicious admin account creation
- Monitoring: Enable alerting on web shell file writes and outbound connections to unknown IPs from web servers
SOURCES
The Hacker News (primary and multiple follow-up articles); BleepingComputer; CSO Online; SecurityWeek; news4hackers
Status: CONFIRMED / ACTIVE EXPLOITATION IN PROGRESS
Recent high-severity events at publish time:

