🔴 CVE-2026-75650

CVE-2026-75650 ('StyleSmuggler') is a CVSS 10.0 server-side template injection (CWE-1336) vulnerability in Adobe Commerce and Magento Open Source that enables unauthenticated remote code execution on the underlying server. It is actively exploited in the wild, listed in CISA KEV, and requires no user interaction or authentication. E-commerce platforms are almost universally internet-facing, making this a critical direct-exploitation risk.

← Back to Overview
HIGH_RISK
Risk Level
10.0
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-07

Added to CISA KEV: 2026-09-08 1 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-09-14)

Summary

CVE-2026-75650, also known as "StyleSmuggler," is a critical-severity (CVSS 10.0) vulnerability affecting Adobe Commerce and Magento [1][2]. Classified as an Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336), this flaw allows unauthenticated remote attackers to perform arbitrary code execution (RCE) on the underlying server [3][4]. This vulnerability is highly significant because it enables attackers to bypass security boundaries entirely, posing an immediate and severe risk to the integrity and confidentiality of affected e-commerce platforms [2].

Exploitation

  • Active Exploitation: The vulnerability is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog [5].
  • Threat Actors: While specific threat actor names are not detailed, reports indicate that the exploitation involves sophisticated operators who have used this zero-day to deploy malicious implants and backdoors [1].
  • Availability: Proof-of-concept exploits or automated attack tools are being utilized by malicious actors in the wild [1].
  • Prerequisites: Exploitation is remote and does not require authentication or user interaction [4].

Affected Products & Patches

  • Affected Versions: Adobe Commerce and Magento are the affected product lines [1].
  • Patch/Hotfix: Adobe has released Security Bulletin APSB26-146, which includes a mandatory hotfix (VULN-39341). This should be applied as a composer patch via `repo.magento.com` [1][6].
  • Mitigations: If an immediate patch is impossible, organizations should attempt to restrict the use of PHP code evaluation within Magento templates via configuration settings (e.g., "disallow_php_in_templates") [3]. Security vendors recommend deploying real-time protection tools (like Sansec Shield) and running scanners (like eComscan) to detect existing implants or backdoors [1].

Impact

  • System Access: Successful exploitation provides attackers with remote code execution capabilities, allowing them to execute arbitrary commands in the context of the current user [4].
  • Business Risk: For internet-facing e-commerce deployments, this vulnerability represents a critical risk, enabling full server compromise, potential data breaches (including customer and payment information), and the persistence of unauthorized access through secondary backdoors [1][2].

Sources

  1. StyleSmuggler: Magento and Adobe Commerce 0-day ...

    Sansec discovered StyleSmuggler, a Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. ... StyleSmuggler is now CVE-2026-75650, scored CVSS 10.0. The fix ships as a hotfix, not as a full release. Download VULN-39341-composer-patches.zip from repo.magento.c…

  2. CVE-2026-75650 | Adobe Commerce and Magento Vulnerability | UpGuard

    "CVE-2026-75650 is a maximum-severity (CVSS 10.0) vulnerability in Adobe Commerce and Magento that allows for unauthenticated arbitrary code execution. As a template injection flaw, it enables attackers to bypass security boundaries and execute malicious commands directly on the server.

  3. CVE-2026-75650 - Vulnerability Details - OpenCVE

    OpenCVE Recommended Actions Apply the Adobe official patch for CVE‑2026‑75650 as soon as it becomes available through Adobe’s security bulletins. If a patch cannot be applied immediately, disable or restrict the use of PHP code evaluation within Magento templates via configuration settings (e.g., "d…

  4. CVE-2026-75650 - Exploits & Severity - Feedly

    CVE info copied to clipboard. Summary. Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. Impact. An unauthenticated attacker over the network can execu…

  5. CISA Adds Four Known Exploited Vulnerabilities to Catalog

    CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability; CVE-2026-81963 ...