Adobe has released an emergency security patch for a critical zero-day vulnerability in its Magento and Adobe Commerce platforms that is being actively exploited in the wild to install persistent backdoors on servers.
The vulnerability, tracked as CVE-2026-75650 and dubbed "StyleSmuggler," carries a maximum-severity CVSS score of 10.0. It affects multiple versions of both the open-source Magento platform and Adobe Commerce, according to a BleepingComputer report and the corresponding Adobe security advisory published Thursday.
What makes the flaw particularly dangerous is the nature of the payload it delivers. Once exploited, the vulnerability allows attackers to implant a backdoor designed to persist across server reboots and survive standard cleanup procedures. This means that simply patching the vulnerability after a breach does not necessarily remove an existing compromise, as the backdoor is engineered to evade basic remediation efforts.
Adobe's advisory outlines that administrators who have not yet patched must apply the emergency update immediately. For those unable to deploy the patch without delay due to operational constraints, Adobe recommends implementing a Web Application Firewall rule to block the known attack vectors as a temporary measure.
However, Adobe also cautioned that patching alone is insufficient for any system that may have already been compromised. The company advises operators to conduct a forensic audit of their servers, checking for unauthorized administrator accounts, suspicious file modifications, and other signs of anomalous activity. Systems found to have been breached should be restored from a known-good backup taken prior to the compromise.
The combination of a perfect severity score, confirmed in-the-wild exploitation, and a persistent payload makes CVE-2026-75650 one of the most significant e-commerce security incidents this year. Magento and Adobe Commerce are widely used to power online retail storefronts globally, meaning the potential scope of exposure is considerable.
Adobe 已針對其 Magento 及 Adobe Commerce 平台中的一個重大零日漏洞發布緊急安全補丁,該漏洞正於現實環境中被積極利用,在伺服器上安裝持久性後門。
此漏洞編號為 CVE-2026-75650,暱稱「StyleSmuggler」,其 CVSS 嚴重性評分為滿分 10.0 分。根據 BleepingComputer 的報導及 Adobe 於週四發布的相應安全公告,此漏洞影響開源 Magento 平台及 Adobe Commerce 的多個版本。
該漏洞特別危險之處在於其有效載荷的本質。一旦被利用,此漏洞允許攻擊者植入一個設計為能經受伺服器重啟、並能在標準清理程序中存活下來的後門。這意味著在發生入侵後,僅僅修補漏洞並不一定能移除已存在的入侵後門,因為該後門旨在規避基本的補救措施。
Adobe 的公告指出,尚未打補丁的管理員必須立即套用此緊急更新。對於因營運限制而無法立即部署補丁的情況,Adobe 建議實施一條 Web 應用程式防火牆(WAF)規則,以暫時阻斷已知的攻擊向量。
然而,Adobe 亦提醒,對於任何可能已被入侵的系統,僅僅打補丁是不足夠的。該公司建議營運商對其伺服器進行取證審計,檢查是否存在未經授權的管理員帳戶、可疑的檔案修改以及其他異常活動的跡象。被發現已遭入侵的系統應從入侵前取得的已知完好備份中還原。
結合其滿分的嚴重性評分、已確認的現實環境利用,以及持久性的有效載荷,使得 CVE-2026-75650 成為今年最重要的電子商務安全事件之一。Magento 與 Adobe Commerce 被廣泛用於全球線上零售店面,意味著其潛在的影響範圍相當巨大。
