Adobe has released security updates for Adobe Commerce and Magento Open Source to fix a critical vulnerability that is already being exploited by attackers.
Tracked as CVE-2026-75650 and rated 10.0 on the CVSS severity scale, the flaw has been dubbed “StyleSmuggler” by Sansec, which discovered attacks exploiting the zero-day on September 4, 2026.
Adobe said the vulnerability could allow attackers to execute arbitrary code and confirmed that CVE-2026-75650 has been exploited in the wild against Adobe Commerce merchants.
The vulnerability abuses Magento’s template system through PHP code injection. Attackers can use the flaw to generate a “Payment Transaction Failed Reminder” email, triggering code execution during the process.
The affected versions include Adobe Commerce 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier, 2.4.5-2026-aug and earlier, and 2.4.4-2026-aug and earlier. Adobe Commerce B2B versions 1.5.3-2026-aug and earlier, 1.5.2-2026-aug and earlier, 1.4.2-2026-aug and earlier, 1.3.4-2026-aug and earlier, and 1.3.3-2026-aug and earlier are also affected. Magento Open Source versions 2.4.9-2026-aug and earlier through 2.4.6-2026-aug and earlier are vulnerable.
Adobe has made hotfixes available for affected installations. The company says administrators need to apply the appropriate VULN-39341 patch for their version and rotate their encryption keys to fully address the issue.
The patch comes after Sansec reported active exploitation of the vulnerability, with attackers using it to compromise Magento stores. The attacks have reportedly been used to deploy a Rust-based Linux backdoor that connects to an external server and waits for additional commands.
Other attacks have delivered a PHP dropper that writes a web shell capable of executing arbitrary PHP code on compromised servers.
Disrex, a Netherlands-based cybersecurity company, said a Magento server operated by an e-commerce development platform was compromised just 50 minutes after the first confirmed StyleSmuggler exploitation was reported on September 4 at 10:20 p.m. UTC.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
According to Disrex, the attack effectively turns Magento’s template-processing and dependency-injection functionality into an unauthenticated remote-code-execution chain, allowing attackers to compromise vulnerable installations without first authenticating.



