type: incident ยท created: 2026-09-09 ยท updated: 2026-09-09 ยท tags: [incident, cve, zero-day, e-commerce, magento, web-shell] ยท confidence: high ยท affected_sectors: [retail, technology, finance] ยท au_impact: true
Adobe Patches Critical Magento Zero-Day Exploited to Backdoor Servers
Adobe released a security update for a maximum-severity, actively exploited Adobe Commerce (Magento) vulnerability dubbed "StyleSmuggler", the first scheduled patch window for a zero-day previously reported as exploited to deploy Linux backdoors and PHP web shells on e-commerce servers.
| Attribute | Detail |
|---|---|
| Product | Adobe Commerce / Magento Open Source |
| Flaw | "StyleSmuggler" (max-severity, actively exploited) |
| Impact | Linux backdoors, PHP web shells on e-commerce servers |
| Source | The Hacker News โ Tier 2/4 |
The patch is an escalation of the StyleSmuggler disclosure that the Sunday and Friday digests first carried, now with an official fix available; administrators running Adobe Commerce are urged to apply it immediately given confirmed in-the-wild exploitation by attackers installing persistent backdoors. The ACSC subsequently issued a Critical alert on the same chain, relevant to Australian e-commerce operators.