StyleSmuggler (CVE-2026-75650): Magento, Adobe Commerce Affected by 0-day RCE
StyleSmuggler (CVE-2026-75650): Magento, Adobe Commerce Affected by 0-day RCE
Summary
StyleSmuggler, with the CVE identifier CVE-2026-75650 and the highest CVSS score of 10, is an unauthenticated remote code execution (RCE) zero-day vulnerability actively exploited in the wild against Magento Open Source and Adobe Commerce. Discovered by Sansec, the vulnerability affects every version from 2.4.4 up to and including 2.4.9. Successful exploitation allows attackers to inject malicious PHP code into Magento's template system, which is then executed during the rendering of a "Payment Transaction Failed Reminder" email. Exploitation has been observed in the wild; attackers began leveraging this flaw on September 4 to deploy Linux backdoors on vulnerable instances.
Affected Systems and Applications
Technical Details
The StyleSmuggler exploit operates in two distinct stages:
- Injection (Poisoning): The attacker injects malicious PHP code into a file that Magento writes, such as system logs or failure reports.
- Execution: The attacker deliberately triggers Magento's standard "Payment Transaction Failed Reminder" email. During the email template rendering process, Magento executes the poisoned code. The exploit specifically targets Magento's dependency-injection code scanner classes, redirecting them to execute the poisoned log or report file.
The attack succeeds even when email delivery fails, as the critical code execution occurs during the template rendering phase.
Post-Exploitation: Rust-Based Backdoor
Mitigation
- Apply Adobe Hotfix: Deploy Adobe's VULN-39341 hotfix for CVE-2026-75650. Patching does not clean a compromised store.
- Disable GraphQL: Temporarily disable GraphQL as an interim mitigation measure until patches are fully applied
- Block Dropper Execution: Add
proc_opento PHP'sdisable_functionsdirective - Mount Restrictions: Mount
/tmp,/var/tmp, and/dev/shmwith thenoexecflag to prevent execution of dropped binaries
Compromise Response
If compromise is confirmed, the following remediation steps are recommended:
- Flush session storage (including Redis if used).
- Rotate the Magento encryption key.
- Reset all credentials protected by the encryption key. From Sansec: "Rotate those at the source, not only inside Magento. Rotating the encryption key on its own does not invalidate anything an attacker already read."
- Admin passwords
- REST / SOAP / GraphQL integration tokens
- OAuth client secrets
- Payment gateway API credentials
- Database credentials
- SSH and deploy keys
- Third-party extension API keys
Indicators of Compromise - from Sansec
More detailed indicators are available in Sansec's article, also linked in References below.
What the Cyber Fusion Center is Doing
The CFC is actively monitoring threat intelligence and reports related to StyleSmuggler/CVE-2026-75650. This advisory will be updated if required.
References
- StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack — Sansec
- Magento StyleSmuggler zero-day exploited to deploy Linux backdoor — BleepingComputer
- StyleSmuggler: Magento / Adobe Commerce 0day — SOCRadar
- Adobe Security Bulletin APSB26-146
- Security update for Adobe Commerce - APSB26-146

.avif)


.png)



.webp)