Vulnerabilities

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code.

Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code.

Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day.

Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE).

“Adobe is aware of CVE-2026-75650 being exploited in the wild,” the company notes in its advisory. Adobe also published a KB article with details on the update.

The security defect was patched on Monday, after cybersecurity firm Sansec warned over the weekend that hackers have been exploiting a zero-day flaw in Commerce/Magento to hack online stores.

Attackers started exploiting the issue, dubbed StyleSmuggler, on September 4, injecting code that would be executed by triggering Magento’s standard ‘Payment Transaction Failed Reminder’, without user interaction.

According to Sansec’s updated report, several threat actors have been targeting the vulnerability to deploy backdoors and web shells.

Advertisement. Scroll to continue reading.

Commerce/Magento should apply Adobe’s fixes as soon as possible and rotate their encryption keys and all credentials protected with those keys, including administrative passwords, database credentials, integration tokens, OAuth secrets, SSH and deploy keys, and API keys.

“Rotate those at the source, not only inside Magento. Rotating the encryption key on its own does not invalidate anything an attacker already read,” Sansec notes.

On Tuesday, Adobe released patches for eight additional Commerce vulnerabilities, including two critical-severity privilege escalation flaws and six high-severity security bypass and privilege escalation bugs.

The company also released urgent patches for CVE-2026-82004 (CVSS score of 10/10), an OS command injection defect in Campaign Classic leading to arbitrary code execution.

Fresh ColdFusion security updates were also assigned a priority 1 rating, as they address two critical-severity code execution security weaknesses: CVE-2026-48273 (CVSS score of 9.9/10) and CVE-2026-75746 (CVSS score of 9.1/10), and seven high- and medium-severity issues.

Adobe recommends that all priority 1 updates be applied within three days after they were released.

On Tuesday, Adobe also rolled out fixes for 107 vulnerabilities in Experience Manager, 32 flaws in Acrobat Reader, 8 in Photoshop, 3 in Illustrator, and 1 in Animate. Fixes were also rolled out for Photoshop Mobile.

Adobe says it is not aware of any of the newly resolved vulnerabilities being exploited in attacks, aside from the Commerce/Magento zero-day. Additional information can be found on Adobe’s security advisories page.

Related: SAP Patches Critical Extended Passport Processing Vulnerability

Related: MikroTik Patches Critical Flaws Chained to Hack Routers

Related: N-able Patches Critical Zero-Day in N-central

Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

Related Content

Vulnerabilities

The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities.

Vulnerabilities

Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.

Vulnerabilities

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.

Vulnerabilities

The security defects could be exploited for arbitrary code execution and denial-of-service.

Vulnerabilities

An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts.

Vulnerabilities

The ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges.

Vulnerabilities

Seven of the security defects have a maximum severity rating of 10/10 and could lead to arbitrary code execution.

Vulnerabilities

Nearly half of the security holes, most allowing arbitrary code execution, have been fixed in Adobe’s Experience Manager product.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version