跳到主内容
@wquguru
精选90Cloudflare WAF(Changelog)云与平台

Cloudflare WAF紧急发布:拦截Adobe Commerce零日RCE漏洞(CVE-2026

WAF - WAF Release - 2026-09-10 - Emergency

原文
发到 X
推荐理由

涉及高危活跃利用的零日漏洞修复,必须立即升级WAF规则集并检查服务器安全状态。

This update provides immediate defense against a high-severity, actively exploited zero-day vulnerability targeting Adobe Commerce and Magento Open Source storefronts.

此更新可立即防御针对 Adobe Commerce 和 Magento Open Source 前台的高危、正在被利用的零日漏洞。

Key Findings

关键发现

  • Adobe Commerce and Magento RCE (CVE-2026-75650 / "StyleSmuggler"): Unauthenticated Remote Code Execution (RCE) vulnerability caused by improper neutralization of special elements in the platform's template engine. Unauthenticated attackers can inject arbitrary PHP payloads through style properties to execute system commands and deploy persistent malware.
  • Adobe Commerce 和 Magento RCE(CVE-2026-75650 / "StyleSmuggler"):由于平台模板引擎中特殊元素未正确中和,导致存在未经身份验证的远程代码执行(RCE)漏洞。未经身份验证的攻击者可通过样式属性注入任意 PHP 有效载荷,以执行系统命令并部署持久化恶意软件。

Impact

影响

This emergency rule provides immediate edge-level mitigation and virtual patching, origin applications must be urgently updated. We strongly recommend to apply the hotfix outlined in Adobe Security Bulletin APSB26-146 and immediately rotate all potentially exposed encryption keys, integration tokens, and system credentials, as patching alone does not remediate an existing compromise.

此紧急规则可提供即时的边缘层缓解措施和虚拟补丁,源应用程序必须紧急更新。我们强烈建议应用 Adobe 安全公告 APSB26-146 中概述的热修复程序,并立即轮换所有可能泄露的加密密钥、集成令牌和系统凭据,因为仅打补丁无法修复已发生的入侵。

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...440f5c55N/AAdobe Commerce - Remote Code Execution - CVE:CVE-2026-75650N/ABlockThis is a new detection.
规则集规则 ID旧版规则 ID描述先前操作新操作注释
Cloudflare 托管规则集...440f5c55不适用Adobe Commerce - 远程代码执行 - CVE:CVE-2026-75650不适用阻止这是新的检测。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

关联信息,但可能不是同一事件