September 9, 2026
- Adobe pushed an out-of-band fix on Monday for StyleSmuggler, the Magento and Adobe Commerce zero-day now tracked as CVE-2026-75650 (CVSS 10.0). Sansec dates exploitation to 4 September, with attackers dropping a Rust backdoor and a PHP web shell (The Hacker News, SecurityWeek) — the flaw was unpatched in earlier coverage. · Patch Tuesday & Active Exploitation
in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android