Tendvane

← All articles

SecuritySeptember 8, 2026

The hole in all those online shops has a patch now. It arrived three days late.

Adobe published the fix on 7 September, out of its normal schedule, as advisory APSB26-146. The flaw we wrote about yesterday is now CVE-2026-75650, rated 10.0 out of 10, the top of the scale. It affects Adobe Commerce and Magento Open Source from 2.4.4 through 2.4.9, plus Commerce B2B 1.3.3 through 1.5.3, which is to say a great many independent online shops.

The three-day gap is the story. Exploitation started at 22:20 UTC on 4 September. Sansec, the Dutch firm that went public early rather than wait, recorded one shop being taken over within 50 minutes of that first warning going out, and honeypots logged a dozen attempts from addresses in China and Romania by 7 September. What attackers dropped was a Rust backdoor and PHP web shells. Adobe's instructions to merchants do not stop at installing the patch: they have to apply the VULN-39341 hotfix, then rotate encryption keys, admin passwords, API tokens, payment gateway credentials, database passwords and SSH keys. Sansec's summary is worth repeating exactly. "Patching closes the hole but does not clean a store that was already hit."

Translated for a shopper: a small shop you bought from last weekend might be patched and cleaned, or patched and still backdoored, and there is no way to tell from the page in front of you. So the advice from yesterday holds rather than expires. Pay through PayPal, Apple Pay or Google Pay at independent shops, because then the shop never handles your card number at all. Say no to saving the card for next time. And read the individual lines on your statement instead of just the balance, since a skimmed card gets tested with a small charge before anyone tries a big one.

The second act of a compromised shop is usually an email about your order that wants you to open something. Tendvane's Safety check flags unexpected startup programs and browser extensions, which is what you would want to look at if one of those emails ever got a click it should not have.

Sources

Download Tendvane