Skip to content
See the World Through ScienceA project of ALLATRA

Adobe Issues an Emergency Fix for a Magento Flaw Attackers Are Already Using

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Screenshot of the Magento admin panel dashboard, showing the Magento logo and navigation bar, sales totals, a list of recent orders and a small orders chart.
The Magento admin panel, the store-management dashboard of the e-commerce platform Adobe has just patched out of band. Illustrative screenshot of an earlier release of the software."Magento Admin Panel screenshot" by Antonio Pardo from Neo Tokyo, Japan, via wikimedia, CC-BY-SA-2.0 · CC-BY-SA-2.0

Adobe published an emergency hotfix on Sept. 7 for a flaw in Magento and Adobe Commerce that attackers had been using to break into live online stores since Sept. 4.

Every version of the store software from 2.4.4 through 2.4.9 is affected, according to Sansec, the Dutch e-commerce security company that found the flaw. Merchants running one of those versions need the fix, which Adobe shipped on its own rather than as part of a full release.

The flaw is CVE-2026-75650. Adobe's own CVE record scores it 10.0 on the CVSS severity scale, which tops out at 10, and says it lets an attacker run code on a store over the network, with no action required by anyone there. The record names Adobe Commerce, Adobe Commerce B2B and Magento Open Source as affected.

Sansec says Adobe gave the update its priority 1 rating, the highest it uses. Being up to date was no protection: the first store it saw compromised had Adobe's July and August patches applied and no outstanding security patches.

Stores were being exploited for three days before the hotfix existed, and patching closes the hole but does not clean a store that was already hit. The company tells merchants to scan for signs of a compromise rather than assume they are clear.

Adobe also recommends rotating a store's encryption key and every credential that key protected, including admin passwords, integration tokens and payment gateway credentials. Those should be rotated at the source rather than only inside Magento, according to Sansec's account of the advisory.

Sansec says it has seen no sign so far that the backdoor left on compromised stores has been used, and that it has also found a second, unrelated attacker on some of the same stores.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Adobe Issues an Emergency Fix for a Magento Flaw Attackers Are Already Using

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.