Adobe Commerce & Magento Open Source Zero‑Day (CVE‑2026‑75650) Enables Rust Backdoor & PHP Shell
What It Is — A critical remote‑code‑execution flaw (CVSS 10.0) in Adobe Commerce and Magento Open Source allows an attacker to upload a malicious Rust‑based backdoor and a PHP web‑shell, granting full server control.
Exploitability — Actively exploited in the wild since 4 Sept 2026; public proof‑of‑concepts observed.
Affected Products — Adobe Commerce (formerly Magento) and Magento Open Source (all supported versions prior to the September 2026 patch).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous vulnerability‑management controls that capture patch status as verifiable evidence for auditors.
- An unpatched instance creates a gap in the “secure configuration” control, which maps to dozens of framework objectives (e.g., NIST CSF Identify and Protect).
- Enterprise buyers increasingly demand proof that vendors maintain an up‑to‑date remediation pipeline; a missing patch can erode that trust signal.
Recommended Actions
- Deploy Adobe’s September 2026 security update on all Commerce/Magento instances immediately.
- Verify patch application via automated inventory tools and capture the patch‑install logs as audit evidence.
- Conduct a focused scan for the known Rust backdoor and PHP shell signatures on all web servers.
- Map the remediation activity to the “Patch Management / Vulnerability Remediation” control objective in your control framework and record the evidence in a continuous‑monitoring repository.
- Review change‑management processes to ensure future critical patches are applied within a defined SLA.