Adobe shipped an emergency hotfix for a maximum-severity flaw in Adobe Commerce and Magento on September 7, 2026. The Adobe Commerce vulnerability, CVE-2026-75650, scores a perfect 10.0 CVSS. It gives unauthenticated attackers arbitrary code execution. Adobe confirms the flaw is exploited in the wild.
- CVE: CVE-2026-75650
- CVSS: 10.0 (Critical · CVSSv3)
- Product: Adobe Commerce
- Affected: ≤ 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug, ≤ 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug, ≤ 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug
- Impact: Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
- Status: Exploited in the wild
- Patched in: Hotfix for CVE-2026-7565
- Action: Update to Hotfix for CVE-2026-7565 now
Why this matters
Magento and Adobe Commerce power a huge share of online retail. So a server takeover exposes customer data and payment flows. This Adobe Commerce vulnerability needs no login and no user interaction. Worse, fully patched stores were still hit. The security firm Sansec, which named the bug StyleSmuggler, reproduced the full chain on clean 2.4.7, 2.4.8, and 2.4.9 installs.
The first known victim shows the danger. That store ran 2.4.6-p15 with July and August 2026 patches applied. Being current stopped nothing. Independent trackers estimate the platform handles well over $100 billion in yearly sales. So the exposed attack surface is enormous, and a successful hit installs a persistent backdoor rather than a smash-and-grab.
How the attack works
The flaw is a template-engine injection, classed as CWE-1336. Adobe states the update “resolves a critical vulnerability that could result in arbitrary code execution.” Sansec explains that StyleSmuggler “injects malicious code into Magento’s template system” and uses the styles properties to slip past safeguards.
The exploit runs in two stages. First, the attacker poisons PHP code, often through a generated failure report. Then Magento runs that code while it renders a failed-payment email. Notably, nobody has to open the email for the attack to succeed.
Exploitation status
The exploitation status is confirmed by two sources. Adobe states it “is aware of CVE-2026-75650 being exploited in the wild.” Sansec traced live attacks to September 4, three days before the patch. Read the Sansec research for indicators of compromise.
The activity is not limited to one group. Sansec reports that operators changed their payloads several times a day. A second, separate actor also used the same flaw to drop a web shell. So defenders should assume more than one intruder may have reached exposed stores.
Affected versions
The flaw affects Adobe Commerce and Magento Open Source from 2.4.4 through 2.4.9. Adobe Commerce B2B versions 1.3.3 through 1.5.3 are also affected. Older builds in those branches are vulnerable too.
Patch and mitigation steps
Apply Adobe’s hotfix for CVE-2026-75650 now. Consult the official Adobe advisory APSB26-146 for install steps. Since stores were hit before the fix existed, scan for compromise as well. Finally, rotate the encryption key and every credential it protected, since patching alone does not clean an already-breached store.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!