CRITICALZero Day
Global

Adobe fixes critical Magento zero-day exploited to backdoor servers

·Source: BleepingComputer

Updated:

Executive Summary

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]

Analysis

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]

Indicators of Compromise (1)

CVE (1)
CVE-2026-75650
Source Attribution

Originally published by BleepingComputer on Sep 8, 2026.

Related Threats

CRITICALZero Day

ConnectWise patches critical ScreenConnect authentication failure after five days

ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation. The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the “TransferFiles”

CVE-2026-84869
CSO Online
CRITICALZero Day

Metasploit Wrap Up: This One Goes to Sixteen!

This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Auth

CVE-2025-66516CVE-2025-54988
Rapid7
CRITICALZero Day

Attackers are weaponizing the gap between Chromium fixes and Chrome patches

A new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team , espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities to allow them to launch targeted spear phishing campaigns. Proofpoint, which researched the new attack method along with G

CVE-2026-85046CVE-2026-87491
CSO Online