Adobe has issued an out-of-band security update to close CVE-2026-75650, a critical zero-day vulnerability affecting Magento and Adobe Commerce platforms. The flaw, assigned the highest severity rating, was being actively exploited in the wild to compromise servers and deploy backdoors. Attackers leveraged the vulnerability, nicknamed StyleSmuggler, to gain unauthorized access to e-commerce environments running unpatched versions of the software.
What happened
The vulnerability was discovered and reported while already under exploitation, prompting Adobe to release an emergency patch. No details about the scale of attacks, specific targets, or threat actors have been disclosed. The company confirmed that multiple versions of Magento and Adobe Commerce are impacted, though it did not specify which releases are vulnerable. The patch was made available on Tuesday, but Adobe has not provided a timeline for when the zero-day was first detected or exploited.
What we don’t know yet
Sources do not clarify how long the vulnerability was exploited before discovery, the number of affected servers, or whether any data breaches resulted from the attacks. Adobe has not released indicators of compromise (IoCs) or guidance for detecting signs of exploitation on compromised systems. The identity of the attackers and their motives remain unclear.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 8 Sep 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Follow-up story Follow-up on the Magento zero-day (StyleSmuggler) with Adobe's official patch release.; matched_article_id=517
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=524 slug=adobe-patches-exploited-magento-zero-day-cve-2026-75650 quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: The draft states the patch was made available 'on Tuesday' without confirming this date is explicitly stated in the source. The source only mentions the publication date (Tuesday, 8 September 2026), not the patch release date. The timing of the patch release should be clarified or omitted if uncertain.
- Factual grounding: The draft claims the vulnerability was 'assigned the highest severity rating' but the source only describes it as 'max-severity.' While this is likely synonymous, the exact phrasing in the source should be mirrored or the claim softened (e.g., 'a maximum severity rating').
- Style compliance: The standfirst uses the term 'server backdoors,' which is slightly more dramatic than the source's 'backdoor servers.' While not materially incorrect, the phrasing should align more closely with the source's neutral tone.
- Audience relevance and notability: The draft does not explicitly state the versions of Magento/Adobe Commerce affected, which would be critical for professionals assessing risk. The source notes 'multiple versions' are impacted but does not specify, so this omission is defensible but worth noting.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Reused library image reused image #7
- Linking related stories — Linked 1 relations from 456 candidates
- Publishing — Published adobe-patches-exploited-magento-zero-day-cve-2026-75650
- Mastodon — Posted https://mstdn.social/@hostingpaper/117235986077104919


Discussion · coming soon
Be the first to join the thread when community discussion launches.