Adobe fixes over 170 vulnerabilities, including Commerce Zero-Day

Adobe fixes over 170 vulnerabilities, including Commerce Zero-Day

Adobe has released patches for more than 170 vulnerabilities in its products, including urgent hotfixes for a serious flaw in Adobe Commerce and Magento Open Source that was exploited as a zero-day in the wild.

Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited for remote code execution (RCE) without authentication.

“Adobe is aware that CVE-2026-75650 is being exploited in the wild,” the company states in its report advisory. Adobe has also released one KB article with details about the update.

The vulnerability was patched on Monday after cybersecurity firm Sansec warned over the weekend that hackers were exploiting a zero-day vulnerability in Commerce/Magento to hack online stores.

Attackers began exploiting the issue, dubbed StyleSmuggler, on September 4, injecting code designed to execute without user interaction by triggering Magento’s standard “Payment Transaction Failed Reminder.”

According to Sansec’s updated reportMultiple threat actors have specifically exploited the vulnerability to deploy backdoors and web shells.

Advertising. Scroll to continue reading.

Commerce/Magento should apply Adobe’s fixes as soon as possible and change their encryption keys and all credentials protected by those keys, including admin passwords, database credentials, integration tokens, OAuth secrets, SSH and provisioning keys, and API keys.

“Rotate this at the source, not just within Magento. Rotating the encryption key alone does not invalidate anything an attacker has already read,” notes Sansec.

On Tuesday, Adobe released patches for eight additional Commerce vulnerabilities, including two critical-severity privilege escalation flaws and six high-severity security bypass and privilege escalation flaws.

The company also released urgent patches for CVE-2026-82004 (CVSS score of 10/10), an operating system command injection flaw in Campaign Classic that results in arbitrary code execution.

New ColdFusion security updates were also assigned Priority 1 because they address two code execution critical severity vulnerabilities: CVE-2026-48273 (CVSS score of 9.9/10) and CVE-2026-75746 (CVSS score of 9.1/10), as well as seven high and medium severity issues.

Adobe recommends applying all Priority 1 updates within three days of their release.

On Tuesday, Adobe also rolled out fixes for 107 vulnerabilities in Experience Manager, 32 vulnerabilities in Acrobat Reader, 8 in Photoshop, 3 in Illustrator and 1 in Animate. Fixes have also been made available for Photoshop Mobile.

Adobe says it is not aware of any newly fixed vulnerabilities being exploited in attacks other than the Commerce/Magento zero-day attack. For more information, visit Adobe Safety instructions Page.

Related: SAP fixes critical security vulnerability in advanced passport processing

Related: MikroTik fixes critical bugs caused by hack routers

Related: N-able fixes critical zero day in N-Central

Related: Nightmare Eclipse drops CrowdStrike, Nvidia and Avast zero-day exploits

Leave a Reply

Your email address will not be published. Required fields are marked *