Cybersecurity

Adobe Issues Emergency Fix for StyleSmuggler Flaw

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Adobe Issues Emergency Fix for StyleSmuggler Flaw
Photo: NewUJ
0 0
XWhatsAppTelegramLinkedIn

Adobe published an emergency hotfix on September 7, 2026, for StyleSmuggler, an unauthenticated remote-code-execution flaw in Magento Open Source and Adobe Commerce that attackers had already been exploiting for three days. The fix, cataloged as APSB26-146 and assigned CVE-2026-75650 with the maximum CVSS score of 10.0, arrived after Dutch security firm Sansec first disclosed the bug on September 5 without waiting for a full technical write-up, saying stores were being compromised "right now."

Sansec traced the first attacks to September 4 at 22:20 UTC. The flaw lets an unauthenticated attacker smuggle PHP code into Magento's template engine through "styles" properties, hiding the payload inside files the platform generates for itself, such as failure reports. That planted code runs automatically once Magento sends its routine "Payment Transaction Failed Reminder" email internally, meaning no shopper ever has to open anything for a store to be backdoored. Sansec reproduced the full attack chain on clean installs of Magento 2.4.7, 2.4.8 and 2.4.9, and confirmed the first known victim was a store running 2.4.6-p15 with every 2026 security patch already applied.

Why the three-day gap matters: Adobe's hotfix means every Magento Open Source and Adobe Commerce installation from version 2.4.4 through 2.4.9, plus Adobe Commerce B2B 1.3.3 through 1.5.3, ran with a working, unauthenticated path to full server takeover for three full days before any fix existed. Because Magento and Adobe Commerce power a large share of the world's online stores, that window gave attackers a wide, largely unpatched target list to plant backdoors and access stored payment data.

The fix ships as a hotfix rather than a full platform release: administrators need to download VULN-39341-composer-patches.zip from repo.magento.com and apply it as a composer patch. Sansec is urging store operators to install the patch immediately, then still run its free eComscan tool to check for backdoors planted during the unpatched window, since applying the fix now does not remove code an attacker may have already installed. Store owners who haven't patched should also review cron jobs and background processes for anything unfamiliar and consider temporarily disabling GraphQL until they've confirmed a clean install.

Report / request removal

Related

Comments

No comments yet. Be the first.