Rust Backdoor and PHP Web Shell Deployment Through Content Injection
Adobe issued emergency security updates on Monday to fix a critical zero-day vulnerability in its Commerce and Magento Open Source platforms that threat actors are actively exploiting in real-world attacks.
Latest news
Anker Unveils Playful 45W Charger With Animated Face Display
Google Docs Web Version Still Missing Native Dark Mode
Anthropic-Linked Vulnerability Exploited From China, Targets US and Japan
Text‑Based AI Agents: Your New Digital AssistantsThe vulnerability, assigned CVE-2026-75650 with a perfect CVSS score of 10.0, allows attackers to execute arbitrary code through maliciously crafted content injection. Sansec has named the exploit StyleSmuggler and confirmed it is being used to deploy a Rust-based backdoor alongside a PHP web shell on compromised servers.
Security researchers discovered that attackers are leveraging this flaw to first inject a custom backdoor written in Rust, which provides persistent access to compromised systems. Once inside, threat actors deploy a PHP web shell that enables remote command execution and data exfiltration. The attack chain demonstrates sophisticated understanding of Magento's architecture and content management workflows.
How Are Organizations Defending Against This Active Exploitation?
The vulnerability stems from improper sanitization of stored content, allowing malicious payloads to bypass security controls. Adobe's investigation confirmed that the issue affects both Adobe Commerce and the open-source Magento platform, with no authentication required to exploit it.
Organizations running Magento or Adobe Commerce should immediately apply the patches released on September 8, 2026. Sansec recommends scanning systems for signs of the Rust backdoor and PHP web shell, as these indicators may persist even after patching. The security firm has shared detection signatures to help defenders identify compromised instances.
Threat actors typically chain multiple vulnerabilities to achieve initial access, making this incident particularly concerning for e-commerce platforms handling sensitive customer data and payment information.
What makes CVE-2026-75650 so severe? The vulnerability requires no authentication and enables complete system compromise through content injection, earning it the highest possible CVSS score of 10.0.
Frequently Asked Questions
How can organizations detect if they've been compromised? Security teams should look for unusual Rust processes running on Magento servers and check for unauthorized PHP files in web directories, particularly those with obfuscated code.
When will additional patches or mitigations be available? Adobe has released the initial fixes, but security researchers expect follow-up updates as attackers continue to evolve their tactics against this vulnerability.
The security landscape continues evolving rapidly, with attackers increasingly targeting e-commerce infrastructure for high-value data access. Organizations must maintain constant vigilance and update their defenses accordingly.
Comments
Leave a comment