Abstrakter Code als Symbol fuer eine Sicherheitsluecke

Magento Zero-Day “StyleSmuggler” (CVSS 10.0) Under Active Attack

A maximum-severity flaw rated CVSS 10.0 in Adobe Commerce and Magento Open Source has been under active attack since early September. Tracked as CVE-2026-75650 and dubbed “StyleSmuggler,” the bug lets unauthenticated attackers run arbitrary code remotely on affected online-shop servers.

A flaw in the platform’s own template engine

The vulnerability sits in Magento’s templating engine. Through a GraphQL-reachable endpoint, attackers smuggle PHP code into “styles” properties. That code executes as soon as the store renders its automatic “Payment Transaction Failed Reminder” email – with no login and no user interaction required. Affected releases are Adobe Commerce 2.4.4 through 2.4.9 and Magento Open Source 2.4.6 through 2.4.9.

Exploited as a zero-day

Dutch security firm Sansec spotted the first attacks on September 4 – three days before Adobe’s emergency patch. Intruders deployed a Rust-based Linux backdoor and a PHP web shell, among other payloads. CrowdSec has since counted around 500 distinct IP addresses sending matching requests as of September 9. On September 8, the U.S. agency CISA added the flaw to its Known Exploited Vulnerabilities catalog.

What operators should do now

Adobe ships the hotfix “VULN-39341” via security bulletin APSB26-146. Store operators should apply it immediately and, crucially, inspect their systems for compromise: patching alone does not remove backdoors that attackers may already have planted. Self-hosted operators should pay particular attention to the GraphQL endpoint and any unexpected email templates.

See also  Cyberattack on Berlin State Network: Sensitive Data May Be Affected After All

Source: The Hacker News – Adobe Patches Magento Zero-Day (CVE-2026-75650)

Leave a Comment

Your email address will not be published. Required fields are marked *

Mastodon
Scroll to Top