Adobe Commerce / Magento StyleSmuggler CVE-2026-75650: Unauth RCE Still Sprayed — Patch ≠ Clean

By George Bailey   Published: 09/15/26   Updated: 09/15/26   2 min read

If you run Adobe Commerce or Magento Open Source, treat StyleSmuggler as an incident, not a patch ticket. The max-severity unauthenticated RCE was exploited for days before Adobe’s hotfix — and scanners are still hammering storefronts.

Applying VULN-39341 closes the door. It does not evict whoever already planted a backdoor in pub/media or a fake chronyd.

What happened

Sansec tracked in-the-wild abuse of what became CVE-2026-75650 (“StyleSmuggler”) starting September 4, 2026. Adobe shipped hotfix VULN-39341 under APSB26-146 on September 7. CISA put it on KEV September 8 with a federal due date of September 11.

The bug is improper neutralization of special elements in the template engine (CWE-1336): attackers plant PHP via style / GraphQL / PayPal response paths, then trigger Magento’s “Payment Transaction Failed Reminder” render path so the store executes the payload — no admin login, no user click on the email.

CrowdSec counted roughly 500 unique IPs and thousands of matching requests between September 9 and 13, with mass scanning still in a rapid-escalation phase as of mid-September.

Why it matters

Code execution on the cart and checkout host is card-skimming and customer-PII territory. Backdoors observed so far survive a simple code update.

Being current on the August security line is not enough — stores on latest 2026-aug builds were still vulnerable until VULN-39341.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.