Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-09 ยท updated: 2026-09-09 ยท tags: [incident, cve, zero-day, e-commerce, magento, web-shell] ยท confidence: high ยท affected_sectors: [retail, technology, finance] ยท au_impact: true

Adobe Patches Critical Magento Zero-Day Exploited to Backdoor Servers

Adobe released a security update for a maximum-severity, actively exploited Adobe Commerce (Magento) vulnerability dubbed "StyleSmuggler", the first scheduled patch window for a zero-day previously reported as exploited to deploy Linux backdoors and PHP web shells on e-commerce servers.

Attribute Detail
Product Adobe Commerce / Magento Open Source
Flaw "StyleSmuggler" (max-severity, actively exploited)
Impact Linux backdoors, PHP web shells on e-commerce servers
Source The Hacker News โ€” Tier 2/4

The patch is an escalation of the StyleSmuggler disclosure that the Sunday and Friday digests first carried, now with an official fix available; administrators running Adobe Commerce are urged to apply it immediately given confirmed in-the-wild exploitation by attackers installing persistent backdoors. The ACSC subsequently issued a Critical alert on the same chain, relevant to Australian e-commerce operators.

Source