Adobe has issued an emergency patch for a critical zero-day vulnerability in its Magento and Adobe Commerce platforms that attackers are already exploiting to backdoor servers. The flaw, tracked as CVE-2026-75650 and dubbed "StyleSmuggler," carries a maximum severity CVSS score of 10.0, placing it among the most serious threats to the e-commerce sector.

According to a BleepingComputer report, the "StyleSmuggler" flaw enables unauthenticated remote code execution. This allows an attacker with no valid credentials to fully compromise a vulnerable store, deploy backdoors, and steal sensitive data, including customer payment details. Adobe's confirmation of active exploitation moves this from a routine update to an urgent incident response.

For IT teams managing their own Magento or Adobe Commerce installations, the directive is clear: apply the security patch immediately. Fixes are available for multiple affected versions, and administrators must consult Adobe's official bulletin to select the correct patch for their environment. Delayed action leaves systems exposed to complete takeover.

Response strategies must differ based on hosting model. Organizations with self-managed servers bear full responsibility for immediate remediation. For those using cloud-hosted or managed Adobe Commerce services, the priority is to confirm with their provider that protective measures have been deployed, as vendors typically handle patching in these setups.

Applying the patch is only the initial step. Given the confirmed exploitation, any system that was vulnerable before the fix must be treated as potentially compromised. Adobe and security experts strongly recommend conducting a forensic audit. This involves searching for unfamiliar administrator accounts, unexpected files, or anomalous database activity that could signal an installed backdoor. Patching addresses the vulnerability but does not remediate an existing breach.

This incident underscores the persistent targeting of e-commerce platforms by financially motivated threat actors. The "StyleSmuggler" zero-day provides attackers a persistent server foothold for data theft, payment skimming, or further network penetration. Adobe's swift, emergency response highlights the gravity of the threat, and all retailers using these platforms must treat this advisory with the highest priority.


Adobe已為其Magento及Adobe Commerce平台的一個關鍵零日漏洞發布緊急補丁,攻擊者正利用該漏洞在伺服器植入後門。該漏洞被追蹤為CVE-2026-75650,代號「StyleSmuggler」,獲得最高的CVSS嚴重性評分10.0,位列電子商務領域最嚴重的威脅之一。

據BleepingComputer報導,「StyleSmuggler」漏洞可實現未經認證的遠端代碼執行。這使得無需有效憑證的攻擊者也能完全入侵易受攻擊的商店、植入後門並竊取敏感資料,包括顧客的支付資訊。Adobe確認該漏洞正遭積極利用,這使事件從常規更新升級為緊急事故應對。

對於自行管理Magento或Adobe Commerce安裝的IT團隊,指示明確:立即應用安全補丁。修補程式已針對多個受影響版本提供,管理員必須查閱Adobe官方公告,以選擇適合其環境的正確補丁。延遲行動將使系統面臨被完全接管的風險。

應對策略必須根據託管模式有所不同。使用自管伺服器的組織須完全負責立即補救。對於使用雲端託管或託管式Adobe Commerce服務的用戶,首要任務是向供應商確認是否已部署保護措施,因為在此類設置中,供應商通常負責處理補丁。

應用補丁只是第一步。鑑於已確認遭積極利用,任何在修復前易受攻擊的系統都必須被視為可能已被入侵。Adobe和安全專家強烈建議進行法證審計。這包括搜尋不熟悉的管理員帳戶、異常檔案或可能顯示已安裝後門的異常資料庫活動。補丁解決了漏洞,但不會補救已存在的入侵。

此次事件突顯了以營利為動機的威脅行為者持續針對電子商務平台。「StyleSmuggler」零日漏洞為攻擊者提供了持久的伺服器立足點,用於竊取資料、竊取支付資訊或進一步滲透網絡。Adobe迅速而緊急的應對突顯了威脅的嚴重性,所有使用這些平台的零售商必須以最高優先級處理此公告。

新聞來源 / Original News Source