news.mlab.sh
Back to the feed
vulnerability

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

CriticalCVSS 10.0
Summary

Adobe has released patches for over 170 vulnerabilities, including a critical zero-day in Adobe Commerce and Magento. A threat actor group, dubbed StyleSmuggler, has been actively exploiting this zero-day to deploy backdoors and web shells. The company urges immediate application of updates and key rotation to mitigate the risk.

Adobe has released patches for more than 170 vulnerabilities across its products, including a critical zero-day flaw in Adobe Commerce and Magento. Tracked as CVE-2026-75650 (CVSS score of 10/10), this code injection issue allows remote code execution (RCE) without user interaction. Cybersecurity firm Sansec warned over the weekend that attackers, known as StyleSmuggler, began exploiting this zero-day on September 4th, injecting code through Magento’s ‘Payment Transaction Failed Reminder’ to deploy backdoors and web shells.

Sansec’s updated report indicates that several threat actors have been targeting this vulnerability. Adobe recommends that Commerce/Magento apply the fixes immediately and rotate their encryption keys and all credentials protected with those keys, including administrative passwords, database credentials, integration tokens, OAuth secrets, SSH and deploy keys, and API keys. Rotating the encryption key alone is not sufficient, as an attacker can still access previously read data.

On Tuesday, Adobe released additional patches for eight Commerce vulnerabilities, including two critical-severity privilege escalation flaws and six high-severity security bypass and privilege escalation bugs. Fresh ColdFusion security updates were also assigned a priority 1 rating, addressing two critical-severity code execution security weaknesses (CVE-2026-48273 and CVE-2026-75746) and seven high- and medium-severity issues. Adobe advises applying priority 1 updates within three days of release.

Furthermore, Adobe released fixes for 107 vulnerabilities in Experience Manager, 32 flaws in Acrobat Reader, 8 in Photoshop, 3 in Illustrator, and 1 in Animate. Updates were also rolled out for Photoshop Mobile. Adobe states it is not aware of any of these vulnerabilities currently being exploited, aside from the Commerce/Magento zero-day. More details can be found on Adobe’s security advisories page.

Read the full article at SecurityWeek