Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day.

Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE).

“Adobe is aware of CVE-2026-75650 being exploited in the wild,” the company notes in its advisory. Adobe also published a KB article with details on the update.

The security defect was patched on Monday, after cybersecurity firm Sansec warned over the weekend that hackers have been exploiting a zero-day flaw in Commerce/Magento to hack online stores.

Attackers started exploiting the issue, dubbed StyleSmuggler, on September 4, injecting code that would be executed by triggering Magento’s standard ‘Payment Transaction Failed Reminder’, without user interaction.

According to Sansec’s updated ...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/dfCZV3VXYy9Efw5WUVLRWW-970-80.jpg

US Army drilled by senators over ‘deep concerns’ surrounding shutdown of cutting-edge drone battalion — and the wars in Ukraine and Iran show that ‘back to basics’ might not be a smart move

* US senators call on Army to answer questions over disbanding of futuristic drone battalion * Letter to General LaNeve raises concerns over US commitment to NATO allies and Ukraine * Drones are changing the face of the battlefield, and the US could miss out on important lessons and innovations A group of