Adobe has released an emergency security update addressing a critical vulnerability affecting Adobe Commerce and Magento Open Source.

Tracked as CVE-2026-75650 and known as StyleSmuggler, the vulnerability can allow an unauthenticated remote attacker to execute arbitrary code on the server.

Even more concerning, Adobe confirms that the vulnerability is already being exploited in the wild.

A Critical CVSS 10.0 Vulnerability

Adobe published security bulletin APSB26-146 on September 7, 2026. The vulnerability is rated Critical with a CVSS score of 10.0.

The issue affects Magento’s template engine and can allow arbitrary code execution without requiring the attacker to authenticate to the store.

  • CVE: CVE-2026-75650
  • Name: StyleSmuggler
  • Severity: Critical
  • CVSS: 10.0
  • Authentication required: No
  • Impact: Remote Code Execution (RCE)
  • Exploitation in the wild: Confirmed by Adobe

Adobe classifies the issue as CWE-1336 — Improper Neutralization of Special Elements Used in a Template Engine.

What is StyleSmuggler?

StyleSmuggler is the name given by security company Sansec to this Magento vulnerability.

Sansec observed the first attacks on September 4, 2026, before the official Adobe fix was released.

The vulnerability is related to the way Magento processes certain data through its template system. Under certain conditions, an attacker can inject malicious content and ultimately achieve code execution on the server.

A successful compromise could potentially result in:

  • e-commerce website modification;
  • backdoor installation;
  • data or credential theft;
  • administrator account compromise;
  • malicious code installation;
  • broader server compromise.

Which Versions Are Affected?

Adobe lists several affected Adobe Commerce and Magento Open Source branches.

Adobe Commerce

  • 2.4.9-2026-aug and earlier
  • 2.4.8-2026-aug and earlier
  • 2.4.7-2026-aug and earlier
  • 2.4.6-2026-aug and earlier
  • 2.4.5-2026-aug and earlier
  • 2.4.4-2026-aug and earlier

Magento Open Source

  • 2.4.9-2026-aug and earlier
  • 2.4.8-2026-aug and earlier
  • 2.4.7-2026-aug and earlier
  • 2.4.6-2026-aug and earlier

Always check Adobe’s official security bulletin for the latest affected versions and available fixes.

View Adobe Security Bulletin APSB26-146

Adobe Has Released an Official Fix

Adobe has released an official hotfix for CVE-2026-75650.

Adobe recommends upgrading affected installations to a secured version or applying the appropriate hotfix for the version currently deployed.

Given the severity of the vulnerability and its confirmed active exploitation, this should be treated as an urgent security update.

⚠️ Important: If your Magento or Adobe Commerce store is running an affected version, do not wait for your next regular maintenance cycle to apply the fix.

Being Patched Does Not Automatically Mean Being Safe

There is an important difference between fixing the vulnerability and checking whether a store has already been compromised.

Since attacks started before the official fix was released, stores that were exposed during this period should be considered potentially compromised until properly checked.

After applying the patch, we recommend:

  1. Reviewing Magento and web-server logs.
  2. Checking for unexpected file modifications.
  3. Reviewing administrator accounts.
  4. Checking API keys and credentials.
  5. Reviewing cron jobs and unexpected processes.
  6. Verifying Magento code integrity.
  7. Rotating secrets if compromise is suspected.
  8. Investigating unusual outbound server connections.

If a compromise is confirmed, applying the patch alone is not enough. The security incident must also be investigated and remediated.

How to Check and Patch a Magento Installation

1. Identify your Magento version

bin/magento --version

2. Check your security patch status

bin/magento security:patch-status

3. Apply Adobe’s security fix

Follow Adobe’s APSB26-146 instructions and apply the hotfix corresponding to your Magento or Adobe Commerce version.

4. Perform a post-patch security review

Do not rely solely on the patch-status command. If your store was exposed before the fix was applied, also review logs, files and administrator accounts.

Magento Security Requires Continuous Maintenance

StyleSmuggler is another reminder that a Magento platform cannot be considered secure simply because it is running correctly in production.

A strong Magento security strategy should include:

  • Magento and Adobe Commerce security updates;
  • continuous vulnerability monitoring;
  • log monitoring;
  • administrator access control;
  • WAF protection;
  • regular backups;
  • security testing;
  • file integrity monitoring;
  • regular credential and secret rotation.

Wemagen — Magento Security and Maintenance

At Wemagen, we help businesses maintain, secure, upgrade and evolve their Magento 2 and Adobe Commerce platforms.

If your store is running a version potentially affected by CVE-2026-75650 / StyleSmuggler, we strongly recommend treating this update as an immediate priority.

Sources