Adobe has released emergency patches to fix a critical zero-day vulnerability in its widely-used Adobe Commerce and Magento Open Source platforms, which attackers were actively exploiting to deploy a sophisticated Rust-based backdoor.
The flaw, tracked as CVE-2026-75650 and carrying a maximum-severity CVSS score of 10.0, was discovered in active exploitation on September 4, 2026. Security researchers at Sansec identified the campaign and codenamed it StyleSmuggler. Adobe's patch followed quickly on September 8, but the window left many high-value e-commerce sites vulnerable.
In a notable tactical evolution, the attackers used the zero-day to plant a backdoor written in the Rust programming language. Rust's memory safety features and compiled binaries can make malware harder for traditional security tools to analyze, representing a growing trend among advanced threat actors aiming for stealth. Alongside the Rust backdoor, attackers also deployed a standard PHP web shell for persistent access.
The vulnerability allowed initial compromise of servers running the affected platforms. With Magento powering a significant portion of global online retail, the implications for payment security and business continuity are substantial. Applying the patch is the immediate priority for all affected administrators.
However, patching alone is insufficient for those who may have been compromised before the fix. Security teams must actively hunt for indicators of compromise (IOCs), specifically scanning for unknown Rust executables and suspicious PHP files on their systems. This incident underscores the need for layered defenses—combining prompt patching with proactive threat hunting and behavior-based detection to counter increasingly sophisticated attack techniques.
Adobe 已發佈緊急補丁,修補其廣泛使用的 Adobe Commerce 及 Magento Open Source 平台中的一個嚴重零日漏洞,攻擊者正積極利用此漏洞部署複雜的 Rust 後門程式。
此漏洞被追蹤為 CVE-2026-75650,CVSS 評分為最高嚴重級別 10.0,已於 2026 年 9 月 4 日被發現正處於活躍利用狀態。網絡安全公司 Sansec 的研究人員識別了此攻擊活動並將其代號定為 StyleSmuggler。Adobe 隨即於 9 月 8 日發佈修補程式,但這段時間差已令眾多高價值電商網站暴露於風險之中。
在一次顯著的戰術演進中,攻擊者利用零日漏洞植入以 Rust 編程語言編寫的後門程式。Rust 的記憶體安全特性與編譯後的二進制代碼,可令惡意軟件更難被傳統安全工具分析,這反映了高級威脅行為者追求隱匿性的增長趨勢。除 Rust 後門外,攻擊者同時部署了標準的 PHP 網頁殼層程式以維持持久存取權限。
此漏洞導致運行受影響平台的伺服器遭初步入侵。由於 Magento 支撐着全球相當大比例的網上零售業務,對支付安全與業務連續性的影響相當重大。立即套用補丁是所有受影響管理員的首要任務。
然而,對於可能在修補前已遭入侵的系統而言,單靠修補並不足夠。安全團隊必須主動搜尋入侵指標(IOC),特別是掃描系統中未知的 Rust 可執行檔及可疑的 PHP 檔案。這次事件突顯了分層防禦的必要性——結合及時修補、主動威脅搜尋及基於行為的檢測,以應對日益複雜的攻擊技術。
