ZoomEye finds 132,158 exposed Magento stores amid CVE-2026-75650
ZoomEye observed 132,158 internet-reachable Magento services on 19 September 2026. CVE-2026-75650 (StyleSmuggler) was exploited from 4 September, Adobe's hotfix VULN-39341 landed on 7 September, and the Rust backdoor survives patching.
- 132,158 Magento services are observable from the internet, per ZoomEye
- The US accounts for 61,553 services, 46.6% of the top-10 countries
- Over 4,200 services run on cPanel ports 2082/2086/2095
- The backdoor impersonates kworker, fc-cache and chronyd and uses UDP 123
Read next
Security