← nejvýznamnější zprávy · všechny zprávy

SPOJENO AI KEV ✓ EPSS 0.02

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]

Číst originál na BleepingComputer →

9 zpráv z 8 zdrojů · první 7. 9. 13:46 · poslední 9. 9. 04:00 CZ · EN/orig

Adobe Magento obchod FI US IT NL FR BE

tg: zneužíváno tg: zranitelnost tg: rozbor tg: propagace tp: malware

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-75650 10.0 3.1 · adobe KEV ✓ 0.02

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.

Jak se o tom psalo 9

  1. · NCSC-FI FI

    Security update available for Adobe Commerce | APSB26-146

    Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-75650, Summary: Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves a critical vulnerability that could result in arbitrary code execution. Adobe is aware of CVE-2026-75650 being exploited in the wild. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS:3.1 10.0

  2. · Tenable Research US

    StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

    A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.Key takeawaysCVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.Active exploitation of CVE-2026-75650 began on September 4, 2026,…

  3. · BleepingComputer US

    Adobe fixes critical Magento zero-day exploited to backdoor servers

    Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]

  4. · CSIRT Itálie (ACN) IT

    Adobe: rilevato sfruttamento in rete della CVE-2026-75650

    Aggiornamenti di sicurezza Adobe sanano una vulnerabilità con gravità “critica” in Adobe Commerce, Adobe Commerce B2B e Magento Open Source, piattaforme per il commercio elettronico utilizzate per la realizzazione e la gestione di siti e servizi di vendita online. Tale vulnerabilità, della quale si evidenzia lo sfruttamento attivo in rete, potrebbe consentire a un attaccante non autenticato di eseguire codice arbitrario sui sistemi interessati.

  5. · NCSC-NL NL

    NCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magento

    Adobe heeft een kwetsbaarheid verholpen in Adobe Commerce en Magento. De kwetsbaarheid bevindt zich in de template engine van Adobe Commerce, waarbij speciale elementen niet correct worden geneutraliseerd. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren zonder dat er gebruikersinteractie nodig is. Dit gebeurt door misbruik te maken van een gewijzigde scope om privileges te escaleren of de uitvoeringcontext aan te passen. Adobe geeft aan dat deze kwetsbaarheid reeds actief…

  6. · CISA KEV US

    Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability (CVE-2026-75650)

    CISA added CVE-2026-75650 to the Known Exploited Vulnerabilities catalog. Affected product: Adobe Commerce and Magento. Remediation due date: 2026-09-11.

  7. · CERT-FR – avis FR

    Vulnérabilité dans les produits Adobe (08 septembre 2026)

    Une vulnérabilité a été découverte dans les produits Adobe. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Adobe indique que la vulnérabilité CVE-2026-75650 est activement exploitée.

  8. · BleepingComputer US nadpis události

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]

  9. · Aikido Security BE

    StyleSmuggler fix: patch the Magento and Adobe Commerce RCE

    StyleSmuggler is an unauthenticated RCE hitting Magento and Adobe Commerce, with no CVE and no Adobe patch yet. Aikido already has the fix. Category: Vulnerabilities & Threats