Adobe Issues an Emergency Fix for a Magento Flaw Attackers Are Already Using

Adobe published an emergency hotfix on Sept. 7 for a flaw in Magento and Adobe Commerce that attackers had been using to break into live online stores since Sept. 4.
Every version of the store software from 2.4.4 through 2.4.9 is affected, according to Sansec, the Dutch e-commerce security company that found the flaw. Merchants running one of those versions need the fix, which Adobe shipped on its own rather than as part of a full release.
The flaw is CVE-2026-75650. Adobe's own CVE record scores it 10.0 on the CVSS severity scale, which tops out at 10, and says it lets an attacker run code on a store over the network, with no action required by anyone there. The record names Adobe Commerce, Adobe Commerce B2B and Magento Open Source as affected.
Sansec says Adobe gave the update its priority 1 rating, the highest it uses. Being up to date was no protection: the first store it saw compromised had Adobe's July and August patches applied and no outstanding security patches.
Stores were being exploited for three days before the hotfix existed, and patching closes the hole but does not clean a store that was already hit. The company tells merchants to scan for signs of a compromise rather than assume they are clear.
Adobe also recommends rotating a store's encryption key and every credential that key protected, including admin passwords, integration tokens and payment gateway credentials. Those should be rotated at the source rather than only inside Magento, according to Sansec's account of the advisory.
Sansec says it has seen no sign so far that the backdoor left on compromised stores has been used, and that it has also found a second, unrelated attacker on some of the same stores.
