Magento zero-day patch urgent warning

Adobe has patched CVE-2026-75650, a CVSS 10.0 zero-day affecting Magento Open Source and Adobe Commerce, following confirmed exploitation in the wild dating back to 4th September 2026. The vulnerability, dubbed StyleSmuggler by the researchers at Sansec who identified it, was being used to deploy a Rust-based backdoor alongside a PHP web shell on compromised storefronts.
A CVSS score of 10.0 is not a rounded-up figure. It reflects a flaw that can be exploited remotely, without authentication, and without any interaction from a user or administrator. In practical terms, that means a publicly accessible Magento instance that has not been patched is fully exposed.
For anyone responsible for an Adobe Commerce or Magento environment, the immediate priority is applying Adobe's patch. The second priority is reviewing your web root and recently modified files for indicators of post-exploitation activity, particularly unexpected PHP files or unfamiliar binaries. If you do not have visibility into file integrity on your storefront, that is a gap worth addressing regardless of this specific vulnerability.
Concerned this affects you?
We can assess your exposure and tell you plainly where you stand.