If you run Adobe Commerce or Magento Open Source, treat StyleSmuggler as an incident, not a patch ticket. The max-severity unauthenticated RCE was exploited for days before Adobe’s hotfix — and scanners are still hammering storefronts.
Applying VULN-39341 closes the door. It does not evict whoever already planted a backdoor in pub/media or a fake chronyd.
What happened
Sansec tracked in-the-wild abuse of what became CVE-2026-75650 (“StyleSmuggler”) starting September 4, 2026. Adobe shipped hotfix VULN-39341 under APSB26-146 on September 7. CISA put it on KEV September 8 with a federal due date of September 11.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
The bug is improper neutralization of special elements in the template engine (CWE-1336): attackers plant PHP via style / GraphQL / PayPal response paths, then trigger Magento’s “Payment Transaction Failed Reminder” render path so the store executes the payload — no admin login, no user click on the email.
CrowdSec counted roughly 500 unique IPs and thousands of matching requests between September 9 and 13, with mass scanning still in a rapid-escalation phase as of mid-September.
Why it matters
Code execution on the cart and checkout host is card-skimming and customer-PII territory. Backdoors observed so far survive a simple code update.
Being current on the August security line is not enough — stores on latest 2026-aug builds were still vulnerable until VULN-39341.
What to do first
- Apply hotfix VULN-39341 (APSB26-146) to every internet-facing Adobe Commerce, B2B, and Magento Open Source instance — including staging.
- Confirm with patch-status checks for 39341; do not assume “security patches applied” from last month’s train.
- Hunt before you relax: unexpected PHP under
pub/media, odd cron entries, processes named likefc-cache/chronydfrom user or temp paths. - Rotate the Magento encryption key, admin passwords, API tokens, and database credentials.
- Until every instance is hotfixed, block obvious exploit shapes at the edge (PHP tags in URL / Store header) — as a bridge, not a substitute.
Details
- CVE: CVE-2026-75650 (CVSS 10.0)
- Products: Adobe Commerce 2.4.4–2.4.9 · Magento Open Source 2.4.6–2.4.9 · Adobe Commerce B2B 1.3.3–1.5.3 (incl. Aug 2026 builds)
- Fix: Hotfix VULN-39341 / APSB26-146 (2026-09-07)
- KEV: Added 2026-09-08; federal due 2026-09-11
- Auth required: None
Hunt / verify
- Verify VULN-39341 present on prod and staging.
- Inventory web shells and unexpected cron since September 4.
- Review outbound NTP-shaped or odd beaconing from the store host.
Sources
- CrowdSec: StyleSmuggler mass scanning report (Sep 14, 2026)
- Adobe APSB26-146 / VULN-39341
- CISA KEV — CVE-2026-75650
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.