INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Adobe Fixes Magento Zero-Day Exploited to Deploy Rust Backdoor

| 2026-09-08 13:34 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE MALWARE & BOTNETS
Executive Summary
AI-generated
The incident data suggests a sophisticated cyber operation involving the exploitation of vulnerabilities in various software products, including Microsoft 365 and Windows Server. The attackers used tactics such as phishing, malware, and rootkit deployment to breach the systems of over 258 organizations. The use of invisible Unicode characters in phishing attacks further highlights the sophistication of the threat. The incident data also reveals a focus on targeted sectors, with cyber operations targeting industries like finance and healthcare.
Technical Mitigations AI-generated
* Use secure protocols: Ensure that all communication between your application and the server is encrypted using HTTPS (Hypertext Transfer Protocol Secure) or TLS (Transport Layer Security). This will prevent eavesdropping and tampering attacks. * Keep software up-to-date: Regularly update your Adobe Commerce and Magento Open Source installation to ensure you have the latest security patches. Use a reputable source, such as the official website or a trusted security vendor, to stay informed about available updates. * Implement secure coding practices: Follow best practices for secure coding, such as using input validation and sanitization, and avoiding common web application vulnerabilities like SQL injection and cross-site scripting (XSS). * Use secure authentication mechanisms: Ensure that your authentication mechanism is secure by using strong passwords, multi-factor authentication, and validating user input carefully. * Monitor system logs and perform regular security audits: Regularly review system logs to detect potential security incidents. Perform thorough security audits on your application and infrastructure to identify vulnerabilities and weaknesses.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

bi•••@bl•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
bi•••••.toulas
re•••••.magento
ad•••••.com
ww•••••.com
10•••••.jpg
10•••••.jpg
10•••••.jpg
10•••••.png
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters CVE-2026-75746CVE-2026-75746 CVE-2026-48273CVE-2026-48273 CVE-2026-75650CVE-2026-75650 CVE-2026-82004CVE-2026-82004
Target & Sectors
BENELUX BENELUX NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2016 August
Threat actors exploited a Magento zero-day vulnerability to gain unauthorized access and backdoor servers using Windows Server 2016 August updates.
infrastructure Windows
tactic T1584.004 - Server
infrastructure 2016 Windows Server
‎August 2026
Adobe released a hotfix for its e-commerce products to address CVE-2026-75650, which exploits a zero-day vulnerability in Adobe Commerce versions 2.4.4 through 2.4.9 and Adobe Commerce B2B versions 1.3.3 through 1.5.3.
vulnerability CVE-2026-75650
infrastructure 2.4.4
infrastructure 2.4.9
infrastructure 1.3.3
infrastructure 1.5.3
infrastructure 2.4.6
organisation Magento Open Source
organisation OAuth
organisation API
organisation SSH
organisation The Blue Report 2026
organisation EU CRA
‎September 4, 2026
Threat actors used a zero-day exploit in Adobe's Adobe Photoshop software to target servers managed by the e-commerce development platform Magento.
target_region Netherlands
organisation Disrex
general_metric 50 minutes
vulnerability CVE-2026-75650
organisation StyleSmuggler
organisation Sansec
‎at least September 4
Sansec discovered that the flaw has been exploited in attacks since at least September 4 to plant a backdoor on vulnerable websites.
organisation Sansec
‎September 7, 2026
Threat actors used IP addresses from China and Romania to exploit a critical Magento zero-day vulnerability.
organisation IP
target_region China
target_region Romania
general_metric 12 exploitation attempts
‎2026/09/07
Adobe fixed a StyleSmuggler zero-day exploit in Adobe Commerce and Magento with yesterday's security update.
organisation StyleSmuggler
‎September 8, 2026
Threat actors used a newly discovered Adobe vulnerability to exploit a critical Magento zero-day that allowed them to backdoor servers.
general_metric 0 09:34 AM
vulnerability CVE-2026-75650
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
organisation Network Time Protocol
organisation NTP
‎Sep 08, 2026
Threat actors exploited a previously unknown critical vulnerability in Adobe's popular e-commerce platform Magento to gain unauthorized access and install a backdoor on targeted servers.
‎2003 - 2026
Threat actors used Adobe's software to exploit a critical Magento zero-day vulnerability and backdoor servers.
organisation Social & Feeds
‎2.4.6-2026-aug
Adobe fixes critical Magento zero-day exploited to backdoor servers.
general_metric 2026 Blue Report
infrastructure 2.4.9-2026
infrastructure 2.4.8-2026
infrastructure 2.4.7-2026
infrastructure 2.4.6-2026
infrastructure 2.4.5-2026
infrastructure 2.4.4-2026
infrastructure 1.5.3-2026
infrastructure 1.5.2-2026
infrastructure 1.4.2-2026
infrastructure 1.3.4-2026
infrastructure 1.3.3-2026
observable repo.magento
observable VULN-39341-composer-patches.zip
‎1.3.4-2026-aug and
The threat actors exploited a critical Magento zero-day vulnerability in Adobe Commerce and B2B products.
general_metric 2026 Blue Report
infrastructure 2.4.9-2026
infrastructure 2.4.8-2026
infrastructure 2.4.7-2026
infrastructure 2.4.6-2026
infrastructure 2.4.5-2026
infrastructure 2.4.4-2026
infrastructure 1.5.3-2026
infrastructure 1.5.2-2026
infrastructure 1.4.2-2026
infrastructure 1.3.4-2026
infrastructure 1.3.3-2026
observable repo.magento
observable VULN-39341-composer-patches.zip
‎2.4.4-2026-aug
Adobe released hotfix patches for affected versions of Adobe Commerce and B2B, as well as Magento Open Source.
general_metric 2026 Blue Report
infrastructure 2.4.9-2026
infrastructure 2.4.8-2026
infrastructure 2.4.7-2026
infrastructure 2.4.6-2026
infrastructure 2.4.5-2026
infrastructure 2.4.4-2026
infrastructure 1.5.3-2026
infrastructure 1.5.2-2026
infrastructure 1.4.2-2026
infrastructure 1.3.4-2026
infrastructure 1.3.3-2026
observable repo.magento
observable VULN-39341-composer-patches.zip
‎2.4.5-2026-aug
Adobe fixes critical Magento zero-day exploited to backdoor servers.
general_metric 2026 Blue Report
infrastructure 2.4.9-2026
infrastructure 2.4.8-2026
infrastructure 2.4.7-2026
infrastructure 2.4.6-2026
infrastructure 2.4.5-2026
infrastructure 2.4.4-2026
infrastructure 1.5.3-2026
infrastructure 1.5.2-2026
infrastructure 1.4.2-2026
infrastructure 1.3.4-2026
infrastructure 1.3.3-2026
observable repo.magento
observable VULN-39341-composer-patches.zip
‎2.4.7-2026-aug and earlier
Adobe fixes critical Magento zero-day exploited to backdoor servers.
general_metric 2026 Blue Report
infrastructure 2.4.9-2026
infrastructure 2.4.8-2026
infrastructure 2.4.7-2026
infrastructure 2.4.6-2026
infrastructure 2.4.5-2026
infrastructure 2.4.4-2026
infrastructure 1.5.3-2026
infrastructure 1.5.2-2026
infrastructure 1.4.2-2026
infrastructure 1.3.4-2026
infrastructure 1.3.3-2026
observable repo.magento
observable VULN-39341-composer-patches.zip
‎2.4.6-2026-aug and earlier
Threat actors exploited a critical Magento zero-day vulnerability in Adobe Commerce and B2B products.
general_metric 2026 Blue Report
infrastructure 2.4.9-2026
infrastructure 2.4.8-2026
infrastructure 2.4.7-2026
infrastructure 2.4.6-2026
infrastructure 2.4.5-2026
infrastructure 2.4.4-2026
infrastructure 1.5.3-2026
infrastructure 1.5.2-2026
infrastructure 1.4.2-2026
infrastructure 1.3.4-2026
infrastructure 1.3.3-2026
observable repo.magento
observable VULN-39341-composer-patches.zip
‎2.4.9-2026-aug
Adobe fixes critical Magento zero-day exploited to backdoor servers.
general_metric 2026 Blue Report
infrastructure 2.4.9-2026
infrastructure 2.4.8-2026
infrastructure 2.4.7-2026
infrastructure 2.4.6-2026
infrastructure 2.4.5-2026
infrastructure 2.4.4-2026
infrastructure 1.5.3-2026
infrastructure 1.5.2-2026
infrastructure 1.4.2-2026
infrastructure 1.3.4-2026
infrastructure 1.3.3-2026
observable repo.magento
observable VULN-39341-composer-patches.zip
‎1.5.2-2026-aug and
The threat actors exploited a critical Magento zero-day vulnerability in Adobe Commerce and B2B products.
general_metric 2026 Blue Report
infrastructure 2.4.9-2026
infrastructure 2.4.8-2026
infrastructure 2.4.7-2026
infrastructure 2.4.6-2026
infrastructure 2.4.5-2026
infrastructure 2.4.4-2026
infrastructure 1.5.3-2026
infrastructure 1.5.2-2026
infrastructure 1.4.2-2026
infrastructure 1.3.4-2026
infrastructure 1.3.3-2026
observable repo.magento
observable VULN-39341-composer-patches.zip
‎2026/09/08
Adobe released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.
infrastructure Linux
organisation infosec news
organisation APM
organisation Hackers
organisation WordPress
infrastructure Microsoft 365
organisation BigBear Microsoft 365
organisation MFA
victims 258 organizations
organisation Unicode
infrastructure Windows
organisation Stack Protection
organisation Windows Registry
organisation the Windows Registry
organisation Adobe Commerce
organisation PHP
data_breach 485 byte PHP web shell
organisation CVE-2026-75650
organisation Magento Open Source
organisation Vulnerability / Web Security
organisation Adobe Commerce
organisation Magento
organisation Adobe
infrastructure 10.0
threat_actor ShinyHunters
organisation DMV
organisation DoppelCart
organisation IP
organisation safely.jpg
organisation ThreatLocker
organisation CTI
organisation Upcoming Webinar
organisation Astra
financial $20 $ subscription
organisation Freestar.com
organisation CVE-2026-75746
organisation ColdFusion CVE-2026-48273
organisation CVSS
organisation Deploy Rust Backdoor
‎September 2026
Threat actors exploited a critical Adobe Magento zero-day vulnerability to gain unauthorized access and backdoor servers.
organisation Microsoft
general_metric 966 flaws
general_metric 2 days
‎September 11, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-75650 to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply the fix by September 11, 2026.
vulnerability CVE-2026-75650
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
victims
258
Organizations
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
2,016
Windows Server
Metrics
infrastructure
‎2.4.4
Software Version
Metrics
infrastructure
‎2.4.9
Software Version
Metrics
infrastructure
‎1.3.3
Software Version
Metrics
infrastructure
‎1.5.3
Software Version
Metrics
infrastructure
‎2.4.6
Software Version
Metrics
data_breach
485
Byte Php Web Shell
Metrics
financial
20
$ Subscription
Metrics
infrastructure
‎2.4.9-2026
Software Version
Metrics
infrastructure
‎2.4.8-2026
Software Version
Metrics
infrastructure
‎2.4.7-2026
Software Version
Metrics
infrastructure
‎2.4.6-2026
Software Version
Metrics
infrastructure
‎2.4.5-2026
Software Version
Metrics
infrastructure
‎2.4.4-2026
Software Version
Metrics
infrastructure
‎1.5.3-2026
Software Version
Metrics
infrastructure
‎1.5.2-2026
Software Version
Metrics
infrastructure
‎1.4.2-2026
Software Version
Metrics
infrastructure
‎1.3.4-2026
Software Version
Metrics
infrastructure
‎1.3.3-2026
Software Version
Metrics
infrastructure
‎10.0
Software Version
Intelligence Sources