InfoSec News Nuggets – 09/08/2026
Brief
InfoSec News Nuggets – 09/08/2026
Adobe Fixes Critical Magento Zero-Day Exploited to Backdoor Servers
Adobe released an emergency out-of-cycle patch for CVE-2026-75650, a maximum-severity zero-day dubbed StyleSmuggler affecting Magento Open Source and Adobe Commerce, after e-commerce security firm Sansec discovered attackers exploiting it since September 4 to plant backdoors on vulnerable stores.
The flaw abuses Magento’s template-processing system to inject and execute malicious PHP code, and Sansec confirmed the technique compromised at least one store that was fully current on every prior security update — meaning normal patching discipline alone wasn’t enough to prevent infection.
