StyleSmuggler: Magento / Adobe Commerce RCE now CVE-2026-75650; Adobe APSB26-146 hotfix
Sansec discovery/attack-from-4-Sep chain (template/GraphQL/failed-payment email → Linux backdoor). NEW material: Sansec updated 7 Sep 2026 20:45 UTC — StyleSmuggler is CVE-2026-75650 (CVSS 10.0). Adobe published emergency hotfix APSB26-146 on 7 Sep 2026 ~20:20 UTC (priority 1) as composer patch VULN-39341 from repo.magento.com; Adobe tested against 2026-aug releases of Adobe Commerce 2.4.4–2.4.9, Magento Open Source 2.4.4–2.4.9, and Adobe Commerce B2B 1.3.3–1.5.3. Exploitation continued after July/August 2026 patch levels; Sansec still advises scan/IoC hunt (kworker/fc-cache/chronyd-style implants, rotate encryption key + credentials). Primary Sansec; vendor APSB26-146. NEW 8 Sep wire: BleepingComputer confirms Adobe’s emergency VULN-39341/APSB26-146 hotfix for CVE-2026-75650 and Sansec’s note that a second, unrelated attacker is also exploiting StyleSmuggler to drop a 485-byte PHP web shell exfiltrating via oast.site/Interactsh-style callbacks — rotate secrets and hunt both Linux-backdoor and PHP-webshell IoCs after patching. NEW 8 Sep KEV: CISA added CVE-2026-75650 to the Known Exploited Vulnerabilities catalog on 2026-09-08 (catalog 2026.09.08); product Adobe Commerce and Magento; FCEB dueDate 2026-09-11; forensicTriage Yes. NEW 10 Sep AU: iTnews reports ASD/ACSC critical alert — ACSC is aware of a substantial number of potentially vulnerable Adobe Commerce/Magento instances in Australia; exploitation needs /graphql exposed; StyleSmuggler injects via GraphQL styles properties into files such as payment-failure reports; patch ASAP and chase MSPs.
- Product
- Magento Open Source / Adobe Commerce
- Versions
- Affects current 2.4.x lines per Sansec (reproduced 2.4.7–2.4.9; victim 2.4.6-p15 fully patched). Hotfix VULN-39341 tested on Adobe Commerce / Magento OS 2.4.4–2.4.9 and Commerce B2B 1.3.3–1.5.3 (2026-aug builds).
- CVSS
- 10.0
- Exploited in Australia?
- unknown
- Patch to
- Apply Adobe VULN-39341 / APSB26-146 composer hotfix; confirm with magento-patches status; rotate Magento encryption key and dependent credentials; scan for StyleSmuggler IoCs before assuming clean
Primary: Sansec — StyleSmuggler / CVE-2026-75650 (updated 7 Sep 2026) · Vendor: Adobe APSB26-146 (CVE-2026-75650 hotfix) · CVE: CVE-2026-75650 · iTnews — ASD/ACSC AU StyleSmuggler alert (10 Sep 2026); earlier BC 8 Sep
