Adobe Issues Emergency Fix for StyleSmuggler Flaw

Adobe published an emergency hotfix on September 7, 2026, for StyleSmuggler, an unauthenticated remote-code-execution flaw in Magento Open Source and Adobe Commerce that attackers had already been exploiting for three days. The fix, cataloged as APSB26-146 and assigned CVE-2026-75650 with the maximum CVSS score of 10.0, arrived after Dutch security firm Sansec first disclosed the bug on September 5 without waiting for a full technical write-up, saying stores were being compromised "right now."
Sansec traced the first attacks to September 4 at 22:20 UTC. The flaw lets an unauthenticated attacker smuggle PHP code into Magento's template engine through "styles" properties, hiding the payload inside files the platform generates for itself, such as failure reports. That planted code runs automatically once Magento sends its routine "Payment Transaction Failed Reminder" email internally, meaning no shopper ever has to open anything for a store to be backdoored. Sansec reproduced the full attack chain on clean installs of Magento 2.4.7, 2.4.8 and 2.4.9, and confirmed the first known victim was a store running 2.4.6-p15 with every 2026 security patch already applied.
Why the three-day gap matters: Adobe's hotfix means every Magento Open Source and Adobe Commerce installation from version 2.4.4 through 2.4.9, plus Adobe Commerce B2B 1.3.3 through 1.5.3, ran with a working, unauthenticated path to full server takeover for three full days before any fix existed. Because Magento and Adobe Commerce power a large share of the world's online stores, that window gave attackers a wide, largely unpatched target list to plant backdoors and access stored payment data.
The fix ships as a hotfix rather than a full platform release: administrators need to download VULN-39341-composer-patches.zip from repo.magento.com and apply it as a composer patch. Sansec is urging store operators to install the patch immediately, then still run its free eComscan tool to check for backdoors planted during the unpatched window, since applying the fix now does not remove code an attacker may have already installed. Store owners who haven't patched should also review cron jobs and background processes for anything unfamiliar and consider temporarily disabling GraphQL until they've confirmed a clean install.
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.