Adobe published APSB26-146 (Priority 1) for CVE-2026-75650, a maximum-severity template-injection flaw in Adobe Commerce and Magento Open Source that yields unauthenticated remote code execution. Adobe’s bulletin states it is aware the CVE is being exploited in the wild. CVSS base score is 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Dutch e-commerce firm Sansec tracked the campaign as StyleSmuggler starting September 4. Attackers inject PHP via Magento’s template path, trigger the platform’s “Payment Transaction Failed Reminder” email chain, and land a Rust Linux backdoor (seen as [kworker/u:8:0], later fc-cache) or a compact PHP web shell. Affected branches include Adobe Commerce 2.4.4–2.4.9 (Aug 2026 and earlier), Commerce B2B 1.3.3–1.5.3, and Magento Open Source 2.4.6–2.4.9.
Adobe’s fix is the VULN-39341 hotfix. After install, operators should enable maintenance mode, suspend cron, and rotate secrets at the source — admin passwords, GraphQL/integration tokens, OAuth secrets, payment gateway credentials, database credentials, SSH/deploy keys, and API keys — then flush cache and restore cron. Adobe notes the hotfix was tested against August 2026 releases; other builds are unconfirmed. Tuesday’s broader Adobe Patch Tuesday (APSB26-138 and peers) adds more Commerce fixes but Adobe says only the StyleSmuggler CVE is known exploited among the new set.
The sourced facts: CVSS 10 unauth RCE, Adobe in-wild confirmation, Sansec StyleSmuggler timeline from Sep 4, Priority 1 VULN-39341, mandatory secret rotation after patch. Victim count: Undisclosed. Patch first.
