Adobe Commerce max-severity bug comes under active attack
Brief
Online stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers.
Security firm Sansec is calling the flaw StyleSmuggler because of the way attackers abused Magento’s Style properties to inject malicious code past existing safeguards.
“When the attack succeeds, a backdoor background process is launched. This is a small Rust program that connects to the 99.
- 67. 186 C2 server and waits for commands,” Sansec researchers said in a blog post , adding that the backdoor had not been weaponized at the time of writing.
The flaw, tracked as CVE-2026-75650 , carries a CVSS score of 10. 0 and affects Magento and Adobe Commerce versions 2.
- 4 through 2.
- 9. Magento is the open-source edition of an e-commerce platform used to build and operate online stores.
