CuraSec

Act active

Adobe Magento zero-day CVE-2026-75650 actively exploited to backdoor servers

2026-09-08 15:04 UTC · BleepingComputer · read the source ↗ #magento#zero-day#active-exploitation
  • Engineer — Act: CVE-2026-75650 is actively exploited with a public PoC and an emergency patch available; if you run Magento or Adobe Commerce, update to the patched version immediately and audit server filesystems and web roots for backdoor artifacts.
  • SOC/IR — Act: Active server backdooring via StyleSmuggler means assume-breach posture for any Magento/Adobe Commerce hosts; hunt for unauthorized web shells or modified files in Commerce directories and check for outbound C2 behavior since the vulnerability was first disclosed.
  • Leader — Plan: If your organization runs Magento or Adobe Commerce for e-commerce, confirm with engineering that the emergency patch has been applied and ask whether any servers showed indicators of compromise — active exploitation with backdoor capability could create customer-data exposure requiring disclosure review.
  • Signals: CVE-2026-75650 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.