Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    The Hidden Instructions That Can Hijack AI Agents

    September 9, 2026

    Could GLP-1 Drugs Help You Live a Longer, Healthier Life?

    September 9, 2026

    Sony Bravia 7 II Review

    September 9, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
    Cybersecurity

    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    The Tech GuyBy The Tech GuySeptember 9, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day.

    Advertisement

    Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE).

    “Adobe is aware of CVE-2026-75650 being exploited in the wild,” the company notes in its advisory. Adobe also published a KB article with details on the update.

    The security defect was patched on Monday, after cybersecurity firm Sansec warned over the weekend that hackers have been exploiting a zero-day flaw in Commerce/Magento to hack online stores.

    Attackers started exploiting the issue, dubbed StyleSmuggler, on September 4, injecting code that would be executed by triggering Magento’s standard ‘Payment Transaction Failed Reminder’, without user interaction.

    According to Sansec’s updated report, several threat actors have been targeting the vulnerability to deploy backdoors and web shells.

    Advertisement. Scroll to continue reading.

    Commerce/Magento should apply Adobe’s fixes as soon as possible and rotate their encryption keys and all credentials protected with those keys, including administrative passwords, database credentials, integration tokens, OAuth secrets, SSH and deploy keys, and API keys.

    “Rotate those at the source, not only inside Magento. Rotating the encryption key on its own does not invalidate anything an attacker already read,” Sansec notes.

    On Tuesday, Adobe released patches for eight additional Commerce vulnerabilities, including two critical-severity privilege escalation flaws and six high-severity security bypass and privilege escalation bugs.

    The company also released urgent patches for CVE-2026-82004 (CVSS score of 10/10), an OS command injection defect in Campaign Classic leading to arbitrary code execution.

    Fresh ColdFusion security updates were also assigned a priority 1 rating, as they address two critical-severity code execution security weaknesses: CVE-2026-48273 (CVSS score of 9.9/10) and CVE-2026-75746 (CVSS score of 9.1/10), and seven high- and medium-severity issues.

    Adobe recommends that all priority 1 updates be applied within three days after they were released.

    On Tuesday, Adobe also rolled out fixes for 107 vulnerabilities in Experience Manager, 32 flaws in Acrobat Reader, 8 in Photoshop, 3 in Illustrator, and 1 in Animate. Fixes were also rolled out for Photoshop Mobile.

    Adobe says it is not aware of any of the newly resolved vulnerabilities being exploited in attacks, aside from the Commerce/Magento zero-day. Additional information can be found on Adobe’s security advisories page.

    Related: SAP Patches Critical Extended Passport Processing Vulnerability

    Related: MikroTik Patches Critical Flaws Chained to Hack Routers

    Related: N-able Patches Critical Zero-Day in N-central

    Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    The Hidden Instructions That Can Hijack AI Agents

    September 9, 2026

    Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

    September 8, 2026

    Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft

    September 8, 2026

    Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    September 8, 2026

    OpenAI Agents Hijack Another Victim Website

    September 8, 2026

    North Korean Hackers Deploy New Linux Espionage Toolkit

    September 7, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    The Hidden Instructions That Can Hijack AI Agents

    September 9, 2026

    Could GLP-1 Drugs Help You Live a Longer, Healthier Life?

    September 9, 2026

    Sony Bravia 7 II Review

    September 9, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.