Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe has released security patches to address a critical zero-day vulnerability (CVE-2026-75650) in Adobe Commerce and Magento Open Source, which has been actively exploited in the wild. Attackers are leveraging this flaw to deploy a Rust backdoor and PHP web shells, highlighting a significant risk for e-commerce merchants.
Adobe released security patches on Monday to address a maximum-severity vulnerability impacting Adobe Commerce and Magento Open Source, now tracked as CVE-2026-75650 (CVSS score: 10.0). The vulnerability has been exploited since September 4, 2026, by threat actors. The core issue involves abusing Magento's template system through PHP code injection to generate a "Payment Transaction Failed Reminder" email, triggering code execution.
Affected versions include:
- Adobe Commerce: 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier, 2.4.5-2026-aug and earlier, 2.4.4-2026-aug and earlier
- Adobe Commerce B2B: 1.5.3-2026-aug and earlier, 1.5.2-2026-aug and earlier, 1.4.2-2026-aug and earlier, 1.3.4-2026-aug and earlier, 1.3.3-2026-aug and earlier
- Magento Open Source: 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier
Disrex, a Dutch e-commerce security company, reported that a Magento server managed by an e-commerce development platform was compromised just 50 minutes after the initial StyleSmuggler exploitation. Attackers are using this vulnerability to deploy a Rust-based Linux backdoor that connects to an external server and awaits further instructions. Separately, the issue has been abused to deliver a PHP dropper that writes a web shell capable of executing arbitrary PHP code. Adobe recommends applying the VULN-39341 patch and rotating encryption keys to mitigate the risk.
