CRITICAL 10 CVE-2026-75650 Published 7 Sept 2026

Adobe Commerce Arbitrary Code Execution a.k.a. StyleSmuggler

Worried this affects one of your servers?

StyleSmuggler (CVE-2026-75650): Critical Magento/Adobe Commerce Zero-Day

StyleSmuggler is a critical, unauthenticated remote code execution vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source (versions 2.4.4–2.4.9). Attackers exploited it starting September 4, 2026, three days before a fix existed, and it received a maximum CVSS score of 10.0. 

The flaw injects malicious PHP through Magento's template system and executes it when the store renders a failed-payment email, requiring no login and no user action. Exploitation runs in two stages: the attacker first smuggles PHP code into the platform, then a follow-up request triggers Magento's template engine to execute it. 

Sansec discovered the flaw had been used since at least September 4 to plant a backdoor that disguised its command-and-control traffic as a regular NTP server. Adobe released an emergency out-of-band hotfix (APSB26-146/VULN-39341) on September 7, 2026. 

Important: The hotfix does not clean up a store that was already compromised — merchants must patch, scan for signs of compromise, and rotate encryption keys and all credentials without delay.

Because StyleSmuggler affected every Magento version from 2.4.4 through 2.4.9 — including fully patched, up-to-date stores — it put Adobe Commerce, Adobe Commerce B2B and Magento Open Source stores worldwide at risk of unauthenticated remote code execution, meaning a significant share of the internet's e-commerce infrastructure was exposed for roughly three days before a fix was available. 

Reference: CVE-2026-75650 on NVD

← Back to Security News