{"id":2942,"date":"2026-09-15T06:00:00","date_gmt":"2026-09-15T06:00:00","guid":{"rendered":"https:\/\/netguide.io\/news\/?p=2942"},"modified":"2026-09-15T06:00:00","modified_gmt":"2026-09-15T06:00:00","slug":"magento-adobe-commerce-zero-day-cve-2026-75650-stylesmuggler","status":"publish","type":"post","link":"https:\/\/netguide.io\/news\/de\/2026\/09\/15\/magento-adobe-commerce-zero-day-cve-2026-75650-stylesmuggler\/","title":{"rendered":"Magento-Zero-Day \u201eStyleSmuggler\u201c: Kritische L\u00fccke (CVSS 10.0) wird aktiv ausgenutzt"},"content":{"rendered":"<div id=\"netgu-1801539775\" class=\"netgu-before-content netgu-entity-placement\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-6258556257245998\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-6258556257245998\" \ndata-ad-slot=\"3494115342\" \ndata-ad-format=\"auto\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p class=\"wp-block-paragraph\"><strong>Eine mit dem H\u00f6chstwert CVSS 10.0 bewertete Sicherheitsl\u00fccke in Adobe Commerce und Magento Open Source wird seit Anfang September aktiv ausgenutzt. Die als \u201eStyleSmuggler\u201c getaufte Schwachstelle CVE-2026-75650 erlaubt es unauthentifizierten Angreifern, aus der Ferne beliebigen Code auf betroffenen Shop-Servern auszuf\u00fchren.<\/strong><\/p>\n\n<h3 class=\"wp-block-heading\">Fehler im eigenen Template-System<\/h3>\n\n<p class=\"wp-block-paragraph\">Die L\u00fccke steckt in Magentos Vorlagen-Engine. \u00dcber eine per GraphQL erreichbare Schnittstelle schleusen Angreifer PHP-Code in \u201estyles\u201c-Eigenschaften ein. Ausgef\u00fchrt wird dieser Code, sobald der Shop die automatische E-Mail \u201ePayment Transaction Failed Reminder\u201c rendert \u2013 ganz ohne Anmeldung oder Zutun eines Nutzers. Betroffen sind Adobe Commerce 2.4.4 bis 2.4.9 sowie Magento Open Source 2.4.6 bis 2.4.9.<\/p><div id=\"netgu-3890534570\" class=\"netgu-content netgu-entity-placement\"><aside class=\"deals-top deals-top--compact\">\n\n\t\t\t<h3 class=\"deals-top__title\">Top-Deals<\/h3>\n\t\n\t\t\t<ul class=\"deals-top__list\">\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/ugreen-aluminium-tabletstaender-360-drehbar-hoehenverstellbar\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/2825012_1-150x150.webp\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">UGREEN Aluminium Tabletst\u00e4nder | 360\u00b0 Drehbar &amp; H\u00f6henverstellbar<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">16.91 \u20ac<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<s>20.37 \u20ac<\/s>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-discount\">-17%<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature is-hot\">\n\t\t\t\t\t\t\t109\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/train-sim-world-7-starter-pack-kostenlos-fuer-ps4-ps5-xbox-pc\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/capsule_616x353-11-150x150.jpg\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">Train Sim World 7: Starter Pack kostenlos f\u00fcr PS4, PS5, Xbox, PC<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t55\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/gratis-forschungssuppe-im-clash-of-clans-store\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/2839474_1-150x150.webp\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">Gratis Forschungssuppe im Clash of Clans-Store<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t54\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/samwatch-simple-e-2024-yamwatch-analog-fuer-wearos\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/2839836_1-150x150.webp\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">SamWatch Simple E 2024 + YamWatch Analog f\u00fcr WearOS<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<s>1.39 \u20ac<\/s>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-discount\">-100%<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t53\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/kostenlose-cosmo-box-fuer-brawl-stars\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/opengraph-1-150x150.jpg\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">Kostenlose Cosmo-Box f\u00fcr Brawl Stars<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t52\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t<\/ul>\n\n\t\t\t\t\t<p class=\"deals-top__more\">\n\t\t\t\t<a href=\"https:\/\/netguide.io\/deals\/\">Alle Deals ansehen \u2192<\/a>\n\t\t\t<\/p>\n\t\t\t<\/aside>\n<\/div>\n\n<h3 class=\"wp-block-heading\">Ausnutzung als Zero-Day<\/h3>\n\n<p class=\"wp-block-paragraph\">Die niederl\u00e4ndische Sicherheitsfirma Sansec entdeckte erste Angriffe bereits am 4. September \u2013 drei Tage vor Adobes Notfall-Patch. Die Angreifer installierten unter anderem eine in Rust geschriebene Linux-Backdoor sowie eine PHP-Webshell. Der Dienst CrowdSec z\u00e4hlte seit dem 9. September rund 500 verschiedene IP-Adressen, die passende Anfragen absetzen. Die US-Beh\u00f6rde CISA nahm die L\u00fccke am 8. September in ihren Katalog aktiv ausgenutzter Schwachstellen auf.<\/p>\n\n<h3 class=\"wp-block-heading\">Was Betreiber jetzt tun sollten<\/h3>\n\n<p class=\"wp-block-paragraph\">Adobe stellt mit dem Sicherheits-Bulletin APSB26-146 den Hotfix \u201eVULN-39341\u201c bereit. Shop-Betreiber sollten ihn umgehend einspielen und ihre Systeme zus\u00e4tzlich auf Kompromittierung pr\u00fcfen: Das reine Patchen entfernt bereits eingerichtete Hintert\u00fcren nicht. Wer die betroffenen Versionen selbst hostet, sollte den GraphQL-Endpunkt und ungew\u00f6hnliche E-Mail-Vorlagen besonders im Blick behalten.<\/p>\n\n<p class=\"wp-block-paragraph\">Quelle: <a href=\"https:\/\/thehackernews.com\/2026\/09\/adobe-patches-magento-zero-day.html\" target=\"_blank\" rel=\"noopener\">The Hacker News \u2013 Adobe Patches Magento Zero-Day (CVE-2026-75650)<\/a><\/p><div id=\"netgu-108681339\" class=\"netgu-after-content netgu-entity-placement\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-6258556257245998\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-6258556257245998\" \ndata-ad-slot=\"4559785002\" \ndata-ad-format=\"auto\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Eine mit dem H\u00f6chstwert CVSS 10.0 bewertete Sicherheitsl\u00fccke in Adobe Commerce und Magento Open Source wird seit Anfang September aktiv [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1722,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[109,13],"tags":[],"class_list":["post-2942","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-news"],"brizy_media":[],"_links":{"self":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/2942","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/comments?post=2942"}],"version-history":[{"count":1,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/2942\/revisions"}],"predecessor-version":[{"id":2965,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/2942\/revisions\/2965"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/media\/1722"}],"wp:attachment":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/media?parent=2942"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/categories?post=2942"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/tags?post=2942"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}