Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.

Sansec says attackers exploit an unpatched Magento and Adobe Commerce flaw to run server code without authentication and install persistent backdoors.

Hackers are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor vulnerable online stores.