Commerce Platforms & DTC
Magento

StyleSmuggler: Magento Zero-Day CVE-2026-75650 Drops a Rust Backdoor and a PHP Web Shell

TL;DR what:Adobe patched CVE-2026-75650, a CVSS 10. 0 unauthenticated remote code execution flaw in Adobe Commerce and Magento Open Source that Sansec codenamed StyleSmuggler and observed being exploited as. . .
dev.to
September 8, 2026
7
StyleSmuggler: Magento Zero-Day CVE-2026-75650 Drops a Rust Backdoor and a PHP Web Shell
WHAT HAPPENED
aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants. s template system. An attacker injects PHP through the template path used to generate the s own template-processing and dependency-injection code into an unauthenticated remote-code-execution chain. 0 unauthenticated remote code execution flaw in Adobe Commerce and Magento Open Source that Sansec codenamed StyleSmuggler and observed being exploited as a zero-day from September 4, 2026. impact:Attackers get code execution as the web server with no credentials, and observed payloads include a Rust based Linux backdoor that beacons to an external server plus a PHP dropper that writes an arbitrary-PHP web shell on the checkout host.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY