Adobe Patches Critical Commerce Zero-Day Among 170
Adobe has released patches for over 170 security flaws, including an urgent fix for a critical, actively exploited zero-day in Adobe Commerce and Magento

Adobe has released security updates addressing more than 170 vulnerabilities across its product portfolio. The most critical patch is for a flaw in Adobe Commerce and Magento Open Source that is being actively exploited as a zero-day.
Tracked as CVE-2026-75650, this critical vulnerability carries a maximum CVSS score of 10. It is a code injection issue that allows unauthenticated attackers to execute remote code. In its advisory, Adobe states, "Adobe is aware of CVE-2026-75650 being exploited in the wild." The patch was released on Monday after cybersecurity firm Sansec warned over the weekend that hackers were already attacking online stores using the flaw.
The Exploited Commerce Zero-Day
According to Sansec, attackers began exploiting the vulnerability, which they dubbed StyleSmuggler, on September 4. The attack involves injecting malicious code that is automatically executed when Magento's standard 'Payment Transaction Failed Reminder' is triggered, requiring no user interaction. Sansec's updated report indicates several threat actors have used the flaw to install backdoors and web shells on compromised systems.
Adobe and Sansec urge immediate action. Commerce and Magento administrators must apply the provided hotfixes without delay. Also, they must rotate all encryption keys and any credentials protected by those keys. This includes administrative passwords, database credentials, integration tokens, OAuth secrets, and SSH, deploy, and API keys. Sansec warns, "Rotate those at the source, not only inside Magento. Rotating the encryption key on its own does not invalidate anything an attacker already read."
Additional Critical Patches Released
On Tuesday, Adobe followed up with patches for eight more vulnerabilities in Commerce. This batch includes two critical privilege escalation flaws and six high-severity security bypass and privilege escalation bugs.
Another urgent patch addresses CVE-2026-82004, a critical OS command injection vulnerability in Campaign Classic that also has a CVSS score of 10 and can lead to arbitrary code execution. Fresh updates for ColdFusion were given a priority 1 rating, fixing two critical code execution flaws: CVE-2026-48273 (CVSS 9.9) and CVE-2026-75746 (CVSS 9.1), along with seven high- and medium-severity issues.
Adobe recommends installing all priority 1 updates within three days of their release.
Broad Patch Coverage Across Products
The massive update wave extends far beyond Commerce and Campaign. Adobe also released fixes for 107 vulnerabilities in Experience Manager, 32 flaws in Acrobat Reader, 8 in Photoshop, 3 in Illustrator, and 1 in Animate. Updates were also issued for Photoshop Mobile.
Adobe states it is not aware of any exploitation in the wild for these newly patched vulnerabilities, with the sole exception of the Commerce/Magento zero-day. The company directs users to its security advisories page for further details.
The following table summarizes the critical and high-severity vulnerabilities mentioned in the source report:
| Product | CVE Identifier | CVSS Score | Vulnerability Type |
|---|---|---|---|
| Adobe Commerce / Magento | CVE-2026-75650 | 10.0 | Code Injection (RCE) |
| Adobe Campaign Classic | CVE-2026-82004 | 10.0 | OS Command Injection |
| Adobe ColdFusion | CVE-2026-48273 | 9.9 | Code Execution |
| Adobe ColdFusion | CVE-2026-75746 | 9.1 | Code Execution |





