Code Defence Cyber security

Adobe fixes critical Magento StyleSmuggler zero day CVE-2026-75650 exploited to deploy Linux backdoors

Emergency web publishing security updates have been distributed to address an actively exploited zero day vulnerability affecting enterprise e-commerce portals. Threat actors leverage malformed email rendering requests to execute arbitrary code and plant compiled Linux backdoor implants on target web hosting servers.

The vulnerability, tracked as CVE-2026-75650 with a CVSS score of 9.8 and dubbed StyleSmuggler, impacts Adobe Commerce and Magento platform versions 2.4.7, 2.4.8, and 2.4.9. The defect involves unsanitized style attribute parsing inside automated email resend subroutines. Unauthenticated remote actors transmit crafted HTTP payloads to force the web server to execute arbitrary system code, dropping compiled Rust backdoor binaries disguised as kworker and fc-cache processes to establish encrypted command and control connections.

Subverting e-commerce web portals presents severe payment card security and customer data privacy risks. Because Magento installations handle customer billing records, credit card processing scripts, and database connection strings, an unauthenticated host compromise permits threat actors to deploy payment skimmers and exfiltrate customer databases.

– Force immediate installation of emergency security patches published by Adobe across all Adobe Commerce and Magento instances.

– Inspect host process registries and file systems for unauthorized binary files executing under kworker or fc-cache process names.

– Deploy web application firewall inspection rules to intercept malformed HTTP requests targeting Magento email resend endpoints.

– Enforce strict database user permission scoping to prevent web server process threads from modifying underlying database schemas.

E-commerce platform defense requires continuous file integrity monitoring and rigid input parsing controls to ensure online publishing environments remain completely protected from unauthenticated zero-day backdoor delivery. #CodeDefence #Adobe #Commerce #Magento #StyleSmuggler #ZeroDay #Linux #RCE #AppSec
/

Scroll to Top