[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRTQiI8M2Ai3hntD35EmhCYO-ZkUjdFe10xWJiRnQmgg":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"00a950fa-1d99-4cb3-82ad-2786862e38ef","Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day","adobe-patches-over-170-vulnerabilities-including-commerce-zero-day-a25d41","Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek.","Adobe has released critical patches for over 170 vulnerabilities across its product suite. A zero-day flaw in Adobe Commerce and Magento Open Source (CVE-2026-75650) has been actively exploited in the wild, allowing unauthenticated attackers to execute arbitrary code. Threat actors are using this vulnerability to deploy backdoors and web shells on compromised online stores.","Adobe patches over 170 vulnerabilities, including a zero-day in Commerce\u002FMagento.","Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score of 10\u002F10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE). “Adobe is aware of CVE-2026-75650 being exploited in the wild,” the company notes in its advisory. Adobe also published a KB article with details on the update. The security defect was patched on Monday, after cybersecurity firm Sansec warned over the weekend that hackers have been exploiting a zero-day flaw in Commerce\u002FMagento to hack online stores. Attackers started exploiting the issue, dubbed StyleSmuggler, on September 4, injecting code that would be executed by triggering Magento’s standard ‘Payment Transaction Failed Reminder’, without user interaction. According to Sansec’s updated report, several threat actors have been targeting the vulnerability to deploy backdoors and web shells.Advertisement. Scroll to continue reading. Commerce\u002FMagento should apply Adobe’s fixes as soon as possible and rotate their encryption keys and all credentials protected with those keys, including administrative passwords, database credentials, integration tokens, OAuth secrets, SSH and deploy keys, and API keys. “Rotate those at the source, not only inside Magento. Rotating the encryption key on its own does not invalidate anything an attacker already read,” Sansec notes. On Tuesday, Adobe released patches for eight additional Commerce vulnerabilities, including two critical-severity privilege escalation flaws and six high-severity security bypass and privilege escalation bugs. The company also released urgent patches for CVE-2026-82004 (CVSS score of 10\u002F10), an OS command injection defect in Campaign Classic leading to arbitrary code execution. Fresh ColdFusion security updates were also assigned a priority 1 rating, as they address two critical-severity code execution security weaknesses: CVE-2026-48273 (CVSS score of 9.9\u002F10) and CVE-2026-75746 (CVSS score of 9.1\u002F10), and seven high- and medium-severity issues. Adobe recommends that all priority 1 updates be applied within three days after they were released. On Tuesday, Adobe also rolled out fixes for 107 vulnerabilities in Experience Manager, 32 flaws in Acrobat Reader, 8 in Photoshop, 3 in Illustrator, and 1 in Animate. Fixes were also rolled out for Photoshop Mobile. Adobe says it is not aware of any of the newly resolved vulnerabilities being exploited in attacks, aside from the Commerce\u002FMagento zero-day. Additional information can be found on Adobe’s security advisories page. Related: SAP Patches Critical Extended Passport Processing Vulnerability Related: MikroTik Patches Critical Flaws Chained to Hack Routers Related: N-able Patches Critical Zero-Day in N-central Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire N-able Patches Critical Zero-Day in N-centralNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day ExploitsNorth Korean Hackers Deploy New Linux Espionage ToolkitAdobe Commerce Zero-Day Exploited to Backdoor Online StoresModified ScreenConnect Clients Used in Worm-Like CampaignElementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesHPE Patches Critical RCE Vulnerabilities in AOS-CXSangoma Switchvox Vulnerability Exploited in the Wild Latest News Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-DaysThe Hidden Instructions That Can Hijack AI AgentsHackers Return $263 Million Stolen From Liquid NetworkCylake Raises $245 Million Ahead of Cybersecurity Platform BetaSAP Patches Critical Extended Passport Processing VulnerabilityParty’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin TheftMikroTik Patches Critical Flaws Chained to Hack RoutersMathspace Data Breach Exposes Over 1 Million People Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fadobe-patches-over-170-vulnerabilities-including-commerce-zero-day\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F01\u002FCybersecurity_News-SecurityWeek.jpg","2026-09-08T18:37:17+00:00","2026-09-08T20:00:37.645244+00:00",9,[18,21,23,25,27,29],{"name":19,"type":20},"Adobe Commerce","product",{"name":22,"type":20},"Magento Open Source",{"name":24,"type":20},"Adobe Campaign Classic",{"name":26,"type":20},"Adobe ColdFusion",{"name":28,"type":20},"Adobe Experience Manager",{"name":30,"type":20},"Acrobat Reader","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":31,"icon":33,"name":34,"slug":35},null,"Vulnerabilities","vulnerabilities",[37,42,44,49],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":43},{"id":31,"icon":33,"name":34,"slug":35},{"category":45},{"id":46,"icon":33,"name":47,"slug":48},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":50},{"id":51,"icon":33,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[55,59,62,65],{"type":56,"value":57,"context":58},"cve","CVE-2026-75650","Exploited zero-day vulnerability in Adobe Commerce\u002FMagento allowing RCE.",{"type":56,"value":60,"context":61},"CVE-2026-82004","OS command injection vulnerability in Adobe Campaign Classic.",{"type":56,"value":63,"context":64},"CVE-2026-48273","Critical code execution vulnerability in Adobe ColdFusion.",{"type":56,"value":66,"context":67},"CVE-2026-75746","Code execution vulnerability in Adobe ColdFusion."]