CVE-2026-75650 ('StyleSmuggler') is a CVSS 10.0 server-side template injection (CWE-1336) vulnerability in Adobe Commerce and Magento Open Source that enables unauthenticated remote code execution on the underlying server. It is actively exploited in the wild, listed in CISA KEV, and requires no user interaction or authentication. E-commerce platforms are almost universally internet-facing, making this a critical direct-exploitation risk.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-07
Added to CISA KEV: 2026-09-08 1 DAY BETWEEN CVE AND KEV
CVE-2026-75650, also known as "StyleSmuggler," is a critical-severity (CVSS 10.0) vulnerability affecting Adobe Commerce and Magento [1][2]. Classified as an Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336), this flaw allows unauthenticated remote attackers to perform arbitrary code execution (RCE) on the underlying server [3][4]. This vulnerability is highly significant because it enables attackers to bypass security boundaries entirely, posing an immediate and severe risk to the integrity and confidentiality of affected e-commerce platforms [2].
Sansec discovered StyleSmuggler, a Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. ... StyleSmuggler is now CVE-2026-75650, scored CVSS 10.0. The fix ships as a hotfix, not as a full release. Download VULN-39341-composer-patches.zip from repo.magento.c…
"CVE-2026-75650 is a maximum-severity (CVSS 10.0) vulnerability in Adobe Commerce and Magento that allows for unauthenticated arbitrary code execution. As a template injection flaw, it enables attackers to bypass security boundaries and execute malicious commands directly on the server.
OpenCVE Recommended Actions Apply the Adobe official patch for CVE‑2026‑75650 as soon as it becomes available through Adobe’s security bulletins. If a patch cannot be applied immediately, disable or restrict the use of PHP code evaluation within Magento templates via configuration settings (e.g., "d…
CVE info copied to clipboard. Summary. Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. Impact. An unauthenticated attacker over the network can execu…
CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability; CVE-2026-81963 ...