CuraSec

Act active

Adobe Patches Magento Zero-Day (CVSS 10) Exploited to Drop Rust Backdoor

2026-09-08 15:04 UTC · The Hacker News · read the source ↗ #magento#zero-day#web-shell
  • Engineer — Act: Active exploitation since September 4 with public PoC and a CVSS 10.0 rating makes this urgent regardless of low EPSS: patch Adobe Commerce / Magento Open Source to the September 8 release immediately, then audit web roots and build logs for PHP web shells and unexpected Rust binaries introduced after September 4.
  • SOC/IR — Act: Confirmed in-the-wild exploitation predates the patch by four days, meaning Magento estates may already be implanted; hunt for PHP web shell artifacts and Rust-based backdoor indicators (Sansec published IOCs under the StyleSmuggler moniker) and sweep file-integrity and EDR telemetry on Commerce hosts back to September 4.
  • Leader — Plan: Confirm whether Adobe Commerce or Magento Open Source is present in your environment or used by a key e-commerce vendor, then verify engineering has treated this as an emergency patch — active exploitation with a backdoor payload elevates reputational and compliance risk for any org handling payment card data on the affected platform.
  • Signals: CVE-2026-75650 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.