# Magento and Adobe Commerce zero-day vulnerability

> Live situation record from CLSTR: https://clstr.news/situations/magento-and-adobe-commerce-zero-day-vulnerability
> Updated: 2026-09-10T15:07:02.000Z. Sources: 12. Developments: 3.

A critical zero-day vulnerability, known as ‘StyleSmuggler’ (CVE-2026-75650), was identified affecting Magento Open Source and Adobe Commerce platforms. The flaw allows for unauthenticated remote code execution (RCE) by leveraging the GraphQL interface to inject malicious PHP code into system files. This code is triggered during the generation of ‘Payment Transaction Failed Reminder’ emails, allowing for exploitation without the recipient opening the message.

Following the discovery of active exploitation that began around September 4, Adobe released an urgent security hotfix (APSB26-146) on September 7. The vulnerability carries a maximum CVSS score of 10.0. Security experts have noted that while the patch addresses the vulnerability, it does not remediate systems that were already compromised. Adobe has advised merchants to apply the patch and rotate encryption keys and potentially exposed credentials to ensure full security.

Security researchers at Sansec reported that observed malicious payloads include a PHP web shell and a Rust-based Linux backdoor. Adobe confirmed the vulnerability is being exploited in the wild, specifically noting the deployment of a 1.9MB Rust-based implant. This implant is designed to evade detection by masquerading as legitimate system processes, such as ‘chronyd’, and uses a heartbeat pattern disguised as routine NTP traffic to bypass network monitoring.

On September 8, CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, establishing a federal remediation deadline of September 11. Affected versions include Magento Open Source 2.4.7, 2.4.8, and 2.4.9.

## Claims

- Adobe confirmed that CVE-2026-75650 is being actively exploited in the wild. (corroborated by 4 sources)
- Adobe released a security patch (VULN-39341) on September 7, 2026. (corroborated by 4 sources)
- The vulnerability allows for unauthenticated remote code execution. (corroborated by 3 sources)
- Remediation requires both applying the patch and rotating encryption keys and credentials. (corroborated by 3 sources)
- The vulnerability CVE-2026-75650 has a CVSS score of 10.0. (corroborated by 2 sources)
- Sansec codenamed the vulnerability StyleSmuggler. (single source)
- Exploitation of the zero-day vulnerability was observed starting September 4, 2026. (single source)
- Observed payloads include a Rust-based Linux backdoor and a PHP web shell. (single source)

## Timeline

### 2026-09-10: Adobe patches critical Magento vulnerability exploited in the wild

Adobe is patching a critical unauthenticated remote code execution vulnerability (CVE-2026-75650) in Magento and Adobe Commerce that is currently being exploited in the wild by attackers.

2 sources. https://clstr.news/cluster/adobe-patches-critical-magento-vulnerability-exploited-in-the-wild

### 2026-09-08: Adobe Commerce and Magento face critical zero-day vulnerability

Adobe has patched a critical CVE-2026-75650 zero-day vulnerability in Magento and Adobe Commerce that allows unauthenticated remote code execution. Active exploitation has been observed.

6 sources. https://clstr.news/cluster/adobe-releases-critical-security-hotfix-for-magento-and-adobe-commerce

### 2026-09-05: Magento and Adobe Commerce hit by StyleSmuggler zero-day exploit

A zero-day vulnerability named ‘StyleSmuggler’ is allowing unauthenticated attackers to exploit Magento and Adobe Commerce stores, installing persistent Rust-based backdoors via GraphQL and email rendering.

5 sources. https://clstr.news/cluster/magento-and-adobe-commerce-zero-day-vulnerability-exploited

---
Cite as: Magento and Adobe Commerce zero-day vulnerability. CLSTR, https://clstr.news/situations/magento-and-adobe-commerce-zero-day-vulnerability
