Adobe Releases Emergency Patch for Actively Exploited Magento Backdoor Flaw

Adobe has issued an emergency hotfix for CVE-2026-75650, a maximum-severity zero-day in Magento and Adobe Commerce that has been exploited since at least September 4 to plant backdoors. The flaw, named StyleSmuggler, allows arbitrary code execution, and attackers have used it to hide command-and-control traffic as NTP requests. Adobe urges immediate installation of the hotfix and recommends rotating all credentials and secrets after patching.
Sansec's investigation revealed the backdoor concealed its command-and-control traffic within NTP requests, while affected stores emitted "Payment Transaction Failed Reminder" emails as a distinct indicator. Adobe's hotfix, VULN-39341, has only been validated against the August 2026 releases of the impacted product branches.
A second threat actor has since exploited the flaw to install a 485-byte PHP web shell that checks the pub/media directory for write access and exfiltrates data to an oast.site domain. With exploitation escalating, the vendor advises rotating all administrative, API, and database credentials following the patch.
E-commerce operators using affected Adobe Commerce or Magento versions could face severe operational disruption and financial loss. The backdoor's persistence may allow attackers to steal customer payment data or manipulate transactions, potentially exposing shoppers to fraud. The required credential rotation across databases, SSH, and APIs could cause significant downtime for merchants. As exploitation escalates, unpatched stores may become increasingly targeted, impacting the broader digital retail ecosystem's trust and security.