StyleSmuggler: a CVSS 10 Magento and Adobe Commerce zero-day is being exploited — patch and rotate every secret

StyleSmuggler: a CVSS 10 Magento and Adobe Commerce zero-day is being exploited — patch and rotate every secret

Adobe has shipped an emergency hotfix for CVE-2026-75650, nicknamed StyleSmuggler, a CVSS 10.0 flaw that lets an unauthenticated attacker run arbitrary code on Adobe Commerce, Adobe Commerce B2B and Magento Open Source servers. It affects Adobe Commerce 2.4.4–2.4.9, Commerce B2B 1.3.3–1.5.3 and Magento Open Source 2.4.6–2.4.9, including their August 2026 releases. E-commerce security firm Sansec found it being exploited from 4 September, three days before Adobe's advisory (APSB26-146) and hotfix VULN-39341 landed on 7 September. The attack smuggles PHP into Magento's template system and fires it while rendering a “Payment Transaction Failed Reminder” email; observed payloads include a Rust-based Linux backdoor whose command server masquerades as an NTP host, and a second, unrelated crew dropping a tiny PHP web shell. Patching alone is not enough: Adobe's guidance is to apply the hotfix, then put the store in maintenance mode, pause cron, and rotate every secret — admin passwords, integration and OAuth tokens, payment-gateway and database credentials, SSH and API keys — before flushing cache and resuming. Note the hotfix was only tested against the August 2026 patch levels, so stores on older point releases should plan an upgrade rather than assume compatibility. For any team running or hosting Magento-based storefronts, this is a same-day job: check for unexplained failed-payment reminder emails and unfamiliar processes as a first indicator of compromise.

This is a summary by our content curator. Read the original at Sansec: https://sansec.io/research/stylesmuggler-0day.