Blog background
September 15, 2026|Read • 5 Min

StyleSmuggler (CVE-2026-75650): Security Alert for Adobe Commerce and Magento Open Source Stores

Written by
Nikki Kumari
Nikki Kumari
Edited by
Mahaveer Devabalan
Mahaveer Devabalan
StyleSmuggler

Listen Full Blog Here

Last Updated: Sep 15, 2026

Key Takeaways

  • »CVE-2026-75650: StyleSmuggler carries a CVSS score of 10.0 and requires no authentication. It has been actively exploited since September 4.
  • »Apply hotfix VULN-39341 from APSB26-146 immediately, as APSB26-138 does not include this fix. Both must be applied separately.
  • »CISA added CVE-2026-75650 to its Known Exploited Vulnerabilities list on September 8.
  • »Adobe Commerce on Cloud merchants received automatic patches and self-hosted merchants must apply VULN-39341 manually.
  • »Merchants on unsupported versions have no official patch. Upgrading is the only permanent fix.

Adobe has confirmed the active exploitation of a critical zero-day vulnerability in Adobe Commerce and Magento Open Source. Tracked as CVE-2026-75650 and named StyleSmuggler by security firm Sansec, the vulnerability carries a CVSS score of 10.0, the maximum possible severity rating. No authentication is required to exploit the store. Attackers have full control of the store, its database, and every credential it holds once compromised.

Who is Affected?

  • Adobe Commerce
  • Adobe Commerce B2B
  • Magento Open Source
  • All supported versions
  • Unsupported versions including Adobe Commerce 2.4.5 and 2.4.6, as no official patch exists for these

StyleSmuggler Adobe Commerce Store Exploitation: Timeline

 StyleSmuggler Adobe Commerce Store Exploitation

How StyleSmuggler Works

The StyleSmuggler attack runs in two silent stages. First, the attacker injects malicious PHP code into a file Magento writes during normal operation, such as a failure report or log. Second, the attacker triggers Magento's Payment Transaction Failed Reminder email. When Magento renders that template, the injected code executes, requiring no admin action and customer interaction. The store continues processing orders normally while the attacker has full server access.

The implant disguises itself as a legitimate Linux process and restarts automatically via cron. It survives a reboot.

Adobe Commerce Zero-Day Response: What to Do Right Now

Stop letting StyleSmuggler take over your store by applying the following steps on time:

Step 01: Apply the StyleSmuggler hotfix immediately

Apply hotfix VULN-39341 from bulletin APSB26-146, which is Adobe's emergency fix specifically for CVE-2026-75650 and is available from repo.magento.com.

Confirm it has been applied correctly using this command:

vendor/bin/magento-patches -n status | grep "39341"

Step 02: Apply the regular September security update separately

APSB26-138 is Adobe's regular September security release, which does not include the StyleSmuggler fix. Both must be applied independently.

Step 03: Find out whether the store was exposed

If the store was accessible between September 4 and September 7 without the hotfix applied, it may have been compromised before a patch existed. Check for these confirmed indicators of compromise:

  • Unusual PHP files beneath Magento media directories
  • Unexpected Payment Transaction Failed Reminder email activity
  • Unfamiliar Linux processes restarting via cron
  • Unexpected admin accounts or integration tokens

Step 04: Rotate all credentials

Adobe treats credential rotation as part of mandatory remediation, not an optional follow-up. Rotate in this specific order:

  • Adobe Commerce encryption keys
  • Admin passwords
  • Payment gateway API credentials
  • REST, SOAP, and GraphQL integration tokens
  • OAuth client secrets
  • Database credentials
  • SSH and deploy keys

Beyond APSB26-146 Patch: What Exposed Stores Should Do

Applying the hotfix closes the vulnerability but does not remove an existing compromise. Stores that were running without the patch between 4th September and 7th Spetember need a thorough scan to detect any persistent implant, remove any secondary backdoors that StyleSmuggler may have installed, and confirm that no credentials were accessed before the patch was applied.

Adobe Commerce Store Unsupported Versions: Exploitation Risk

Adobe Commerce 2.4.5 and 2.4.6 lost regular support on August 11, 2026, with no official patch for CVE-2026-75650 existing for these versions.

Community backports are there but are not endorsed by Adobe. Therefore, upgrading to a supported release is the only permanent fix for merchants on unsupported versions. Running an unsupported version during an active exploitation campaign is a significant and immediate commercial risk.


Codilar is Providing Ongoing Support

As a digital commerce company with a dedicated DevOps practice, Codilar is currently providing merchants with:

  • Confirming hotfix VULN-39341 and APSB26-138 patch status
  • Running compromise assessments for stores exposed between September 4 and September 7
  • Complete credential rotation across all affected systems
  • Upgrading merchants from unsupported versions to a supported release

Running on Adobe Commerce or Magento Open Source? Reach out to our specialists for immediate support.


Liked what you read? Share with your teamShare

FAQs

Yes, as every Adobe Commerce, Adobe Commerce B2B, and Magento Open Source installation is affected. Adobe Commerce on Cloud merchants received automatic patches and should verify via the Quality Patches Tool. Self-hosted merchants must apply hotfix VULN-39341 manually from repo.magento.com immediately.

No, APSB26-138 does not include the StyleSmuggler fix. Hotfix VULN-39341 from bulletin APSB26-146 must be applied separately. A store that has only applied APSB26-138 remains vulnerable.

Patching is not sufficient, as the StyleSmuggler implant survives the patch. Scan for indicators of compromise, including unusual PHP files under Magento media directories and unexpected Payment Transaction Failed Reminder activity. Complete credential rotation is mandatory regardless of whether compromise is confirmed.

Encryption keys, admin passwords, payment gateway credentials, REST and SOAP and GraphQL tokens, OAuth secrets, database credentials, and SSH keys. Rotating encryption keys first is critical because they protect every other credential the store holds.

No official patch exists for Magento Open Source 2.4.4 or 2.4.5, or for Adobe Commerce on those versions. Thus, upgrading to a supported release is the only permanent fix.

CTA Background

eRetail Growth
in Mind?

Get tailored technology solutions to scale your retail business online

Request A QuoteArrow
CTA Background

Talk to Our
eCommerce
Expert

Book A MeetingArrow
Mail

Subscribe to
Stay in Know

Stay ahead with insights, trends, and brand success stories from the world of Digital Commerce.

Ready to Talk? Pick a Time
Book Calendar
Codilar team at work
USA
Australia
Singapore
KSA
UAE
Oman
Indonesia
India

Build. Optimize. Grow.

With world's leading digital commerce agency.

Full Name*
Official Email*
Mobile No*
Company Name*
Select Services
Message

Want our latest stories
sent straight to your inbox?