Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Adobe patched over 170 vulnerabilities across its product suite, with urgent Priority 1 fixes for multiple critical-severity flaws CVE-2026-75650, a CVSS 10/10 unauthenticated remote code execution vulnerability in Adobe Commerce/Magento, is actively exploited in the wild (dubbed "StyleSmuggler") Additional critical patches address CVE-2026-82004 (OS command injection in Campaign Classic, CVSS 10/10) and two ColdFusion code execution flaws (CVSS 9.9 and 9.1) Experience Manager received the large
Analysis
TL;DR
- Adobe patched over 170 vulnerabilities across its product suite, with urgent Priority 1 fixes for multiple critical-severity flaws
- CVE-2026-75650, a CVSS 10/10 unauthenticated remote code execution vulnerability in Adobe Commerce/Magento, is actively exploited in the wild (dubbed "StyleSmuggler")
- Additional critical patches address CVE-2026-82004 (OS command injection in Campaign Classic, CVSS 10/10) and two ColdFusion code execution flaws (CVSS 9.9 and 9.1)
- Experience Manager received the largest share of fixes with 107 vulnerabilities patched, followed by 32 in Acrobat Reader
- Adobe recommends applying all Priority 1 updates within three days and rotating all encryption keys and credentials at the source
Why It Matters
This represents one of the largest coordinated security patch releases from Adobe, targeting enterprise-critical platforms like Commerce, Campaign Classic, and Experience Manager that power thousands of online businesses. The active exploitation of the Magento zero-day by multiple threat actors deploying backdoors and web shells underscores the urgent need for immediate remediation by e-commerce operators. The breadth of vulnerabilities across Creative Cloud and Document products also highlights ongoing attack surface risks for individual and organizational users.
Technical Details
- CVE-2026-75650 (CVSS 10/10): Unauthenticated code injection in Adobe Commerce/Magento Open Source enabling remote code execution; exploited via the standard "Payment Transaction Failed Reminder" feature without user interaction, dubbed "StyleSmuggler" by Sansec
- CVE-2026-82004 (CVSS 10/10): OS command injection vulnerability in Adobe Campaign Classic leading to arbitrary code execution
- ColdFusion critical flaws: CVE-2026-48273 (CVSS 9.9) and CVE-2026-75746 (CVSS 9.1) are critical code execution weaknesses, plus seven high- and medium-severity issues
- Patch distribution: 107 vulnerabilities in Experience Manager, 32 in Acrobat Reader, 8 in Photoshop, 3 in Illustrator, 1 in Animate, plus Photoshop Mobile fixes
- Eight additional Commerce vulnerabilities patched: Two critical privilege escalation flaws and six high-severity security bypass/privilege escalation bugs
Industry Insight
- Organizations running Magento/Adobe Commerce should treat this as an emergency—apply patches immediately and rotate all credentials (encryption keys, admin passwords, API keys, OAuth secrets) at their source, not just within Magento, since attackers may have already exfiltrated data
- The "StyleSmuggler" attack vector exploiting a built-in payment reminder feature demonstrates how attackers leverage legitimate application functionality for stealthy code injection, a pattern likely to recur across SaaS platforms
- Adobe's Priority 1 patch cadence and three-day remediation window signal the severity expected by enterprise security teams; integrating these updates into emergency patch management workflows is essential for compliance and risk reduction
Disclaimer: The above content is generated by AI and is for reference only.