Adobe has released fixes for more than 170 vulnerabilities across its products, including a critical zero-day in Adobe Commerce and Magento Open Source that was actively exploited in the wild. The exploited flaw, tracked as CVE-2026-75650 and dubbed StyleSmuggler, enabled unauthenticated remote code execution, prompting urgent guidance to patch systems and rotate sensitive credentials. #AdobeCommerce #MagentoOpenSource #CVE202675650 #StyleSmuggler #Sansec
Keypoints
- Adobe patched a critical zero-day in Adobe Commerce and Magento Open Source.
- CVE-2026-75650 could be exploited without authentication for remote code execution.
- Sansec reported active exploitation under the name StyleSmuggler starting September 4.
- Attackers used the flaw to deploy backdoors and web shells on online stores.
- Adobe also released fixes for Campaign Classic, ColdFusion, Experience Manager, Acrobat Reader, Photoshop, Illustrator, Animate, and Photoshop Mobile.
Read More: https://www.securityweek.com/adobe-patches-over-170-vulnerabilities-including-commerce-zero-day/