Adobe releases emergency fixes for exploited Magento RCE flaw

Critical Magento flaw receives emergency fixes
Adobe has released security updates for CVE-2026-75650, a maximum-severity vulnerability affecting Adobe Commerce, Adobe Commerce B2B and Magento Open Source. The flaw carries a CVSS score of 10.0 and has already been exploited against Adobe Commerce merchants.
Sansec, which identified the activity, has named the issue StyleSmuggler. It said zero-day exploitation began on September 4, 2026. Adobe described the vulnerability as a critical issue that can result in arbitrary code execution and confirmed awareness of in-the-wild attacks.
Template processing becomes an execution path
The attack abuses Magento's template system through PHP code injection. Attackers can generate a “Payment Transaction Failed Reminder” email and trigger code execution through that processing path.
Disrex characterised the chain as unauthenticated remote code execution that misuses Magento's own template-processing and dependency-injection code. The company said a Magento server it manages was compromised 50 minutes after the first confirmed StyleSmuggler exploitation, reported at 10:20 p.m. UTC on September 4.
The affected releases include Adobe Commerce 2.4.4 through 2.4.9 with the August 2026 package level or earlier, Magento Open Source 2.4.6 through 2.4.9 with that package level or earlier, and listed Adobe Commerce B2B versions from 1.3.3 through 1.5.3 and earlier August 2026 releases.
Backdoors and web shells raise the incident risk
Sansec reported that attackers used the vulnerability to deploy a Rust-based Linux backdoor. The malware connects to an external server and waits for further instructions. Separately, the weakness has been used to deliver a PHP dropper that writes a web shell capable of executing arbitrary PHP code on compromised sites.
Adobe has made version-specific hotfixes available in the VULN-39341 patch package. Its remediation guidance requires affected customers to apply the appropriate VULN-39341 patch and rotate their encryption keys.
Operational priority for commerce teams
Teams operating affected Magento or Adobe Commerce installations should treat patching and key rotation as immediate incident-response work, while checking servers for unexpected PHP files, web shells and other persistence that may have been installed before remediation.

