Adobe patches 170+ flaws, fixes Commerce/Magento zero-day

Adobe released patches for more than 170 vulnerabilities, including a critical Commerce/Magento zero-day (CVE-2026-75650) exploited in the wild that allows unauthenticated RCE.

Adobe issued security updates addressing over 170 vulnerabilities across its product line, including a critical zero-day in Adobe Commerce and Magento Open Source tracked as CVE-2026-75650. The flaw can allow unauthenticated remote code execution, and the company noted it is being exploited in the wild.

Cybersecurity firm Sansec reported active exploitation beginning on Sept. 4. Attackers used a technique the firm calls StyleSmuggler to inject code that runs when Magento’s standard “Payment Transaction Failed Reminder” is triggered, without any user interaction.

Sansec’s analysis found multiple threat actors deploying backdoors and web shells on compromised stores. The firm urged merchants to apply Adobe’s fixes immediately and to rotate encryption keys and credentials that those keys protect, listing administrative passwords, database credentials, integration tokens, OAuth secrets, SSH and deploy keys, and API keys. Sansec warned, “Rotate those at the source, not only inside Magento. Rotating the encryption key on its own does not invalidate anything an attacker already read.”

Adobe expanded its updates the day after the initial fix, releasing patches for eight additional Commerce vulnerabilities. Those include two critical privilege-escalation flaws and six high-severity bypass and escalation issues. The vendor also issued an urgent patch for an OS command injection defect in Campaign Classic, CVE-2026-82004, with a CVSS score of 10.0 that can lead to arbitrary code execution.

ColdFusion received priority 1 updates for two critical code-execution flaws, CVE-2026-48273 (CVSS 9.9) and CVE-2026-75746 (CVSS 9.1), along with several high- and medium-severity fixes. Adobe recommends applying priority 1 updates within three days of release.

The broader update set includes 107 fixes for Experience Manager, 32 for Acrobat Reader, eight for Photoshop (including Photoshop Mobile), three for Illustrator and one for Animate. Adobe says it is not aware of exploitation of those newly patched vulnerabilities beyond the Commerce/Magento zero-day.

Operators of affected Adobe products are advised to install available updates, search systems for web shells or unexpected backdoors, replace any potentially exposed secrets and examine logs for unusual payment reminder activity or unauthorized administrative actions. Adobe published full details and a knowledge-base article on its security advisories page.

Articles by this author