In short
StyleSmuggler (CVE-2026-75650, CVSS 10.0) is an unauthenticated remote code execution flaw in Magento 2.4.4 to 2.4.9 that attackers exploited before a fix existed. Apply Adobe’s APSB26-146 hotfix (VULN-39341) and the separate APSB26-138 September patch, then assume you may already be compromised: hunt for indicators, rotate your encryption key and every credential it protected, and put a WAF rule in front of the store.
In early September 2026, Magento and Adobe Commerce stores were hit by a zero-day that needed no login, no admin session and no form key. Sansec named it StyleSmuggler. Adobe rated it CVSS 10.0, the highest score possible, and shipped an emergency hotfix three days after the first confirmed attack.
If you run any 2.4.x release from 2.4.4 onward and have not applied the hotfix, treat this as an incident, not routine maintenance. This guide covers what happened, which versions are affected, and the exact steps to patch, investigate and harden your store.
What StyleSmuggler is
CVE-2026-75650 abuses Magento’s email template processing. According to Sansec’s analysis, the attack works in two stages:
- The attacker plants PHP code in a file that Magento writes itself, such as an error report under
var/report/, using a request to the PayPal transparent response endpoint. - A crafted GraphQL request then smuggles template content through
stylesproperties, which slips past existing template safeguards. The attacker triggers Magento’s standard “Payment Transaction Failed Reminder” email, and the injected code runs while Magento renders that email.
Nobody has to open the email. The code executes server-side during rendering. Sansec observed attackers using this to launch a disguised background process that connects to a command-and-control server and waits for instructions.
Timeline
| Date (2026) | Event |
|---|---|
| 23 August | First unsuccessful probes observed by Sansec |
| 4 September, 22:20 UTC | First confirmed exploitation |
| 5 September | Sansec publishes its analysis and deploys blocking rules |
| 7 September | Adobe publishes security bulletin APSB26-146 with hotfix VULN-39341 |
| 8 September | Adobe’s regular September bulletin APSB26-138 ships; Mage-OS 3.5.0 emergency release; CISA adds CVE-2026-75650 to its Known Exploited Vulnerabilities catalog |
Affected versions
Adobe’s APSB26-146 announcement lists these as affected, including the August 2026 releases and earlier:
- Adobe Commerce 2.4.4 through 2.4.9
- Adobe Commerce B2B 1.3.3 through 1.5.3
- Magento Open Source 2.4.4 through 2.4.9
Some third-party write-ups list Magento Open Source from 2.4.6 rather than 2.4.4. Do not rely on that difference: if you run any 2.4.4 or later release, apply the fix.
Releases older than 2.4.4 receive no official patch from Adobe. Sansec reports that a third party has published backports for some older lines, but if you are on 2.4.3 or earlier, the honest answer is that you are running unsupported software with a known critical exploit, and an upgrade plan should start now.
Step 1: Apply the APSB26-146 hotfix
The fix is hotfix VULN-39341, distributed as VULN-39341-composer-patches.zip through Adobe’s announcement and repo.magento.com. Adobe also provides version-specific patch files for some release lines, so download the one that matches your exact version.
Apply it on staging first if you can do so within hours, not days. Given active exploitation, a short maintenance window on production is a reasonable trade-off.
# check your exact version first
bin/magento --version
composer show magento/product-community-edition 2>/dev/null || composer show magento/product-enterprise-edition
# after unzipping, apply the composer patch from the project root
git apply VULN-39341_composer.patch # or: patch -p1 < VULN-39341_composer.patch
bin/magento setup:di:compile
bin/magento cache:flushFollow Adobe’s “How to apply a composer patch provided by Adobe” article for your setup. On Adobe Commerce on Cloud, add the patch to the m2-hotfixes directory and redeploy. Sansec suggests confirming the patch status with the Quality Patches Tool:
vendor/bin/magento-patches -n status | grep "39341\|Status"Step 2: Apply the September APSB26-138 patch as well
APSB26-138, released 8 September 2026, is the regular monthly security update. It fixes eight vulnerabilities, all rated Critical, including stored XSS, incorrect authorization and path traversal issues. Adobe stated it was not aware of exploits in the wild for those issues at release.
The important detail: the StyleSmuggler hotfix is not included in the September isolated patch file. Adobe’s knowledge base article says to apply both. Isolated September patches are available for 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 and 2.4.4-p18.
Step 3: Check for signs of compromise
Exploitation began three days before a patch existed. Patching closes the door but does not remove anyone already inside. Sansec published indicators you can check today.
Processes and cron
Look for background processes posing as system tools, for example names like [kworker/u:8:0], fc-cache or chronyd running as your web user, and for unfamiliar crontab entries.
ps -eo user,pid,ppid,cmd | grep -E "fc-cache|chronyd|kworker" | grep -v grep
crontab -l -u www-data # use your PHP/web userFiles
ls -la ~/.cache/fontconfig/ 2>/dev/null
ls -la /tmp | grep -E "\.fc-|\.chrony-"
find pub/media -name "*.php" -mtime -45
find pub/media/catalog/product/cache -path "*ss_*" -name "sync_*.php"Any PHP file under pub/media is a red flag. That directory should only hold assets.
Logs and network
- Search
var/log/exception.logforLaminas\Loader\Exception\InvalidArgumentException. - Look for bursts of “Payment Transaction Failed” emails in your mail logs or transactional email provider.
- Review web server logs for requests to
/paypal/transparent/response/with unusual query strings and GraphQL POSTs containingstyles. - Check outbound connections from web nodes to the command-and-control addresses Sansec lists, such as
99.84.67.186.
Sansec’s eComscan scanner has detection for StyleSmuggler implants. If you find anything, isolate the server, preserve logs and file timestamps for forensics, and rebuild from a known-clean source rather than deleting files one by one.
Step 4: Rotate the encryption key and every credential
This is the step most teams skip, and Adobe is explicit about it. After applying the hotfix, rotate:
- The Magento encryption key
- All admin passwords
- REST, SOAP and GraphQL integration tokens
- OAuth secrets for third-party apps
- Payment gateway credentials, at the provider
- Database and Fastly credentials
- SSH and deploy keys, plus service accounts
- Third-party API keys for shipping, tax and extensions
Adobe notes that rotating the encryption key alone does not invalidate credentials that may already have leaked. Each secret has to be changed at its source. On Adobe Commerce on Cloud, rerun the deployment after updating credentials so new database credentials take effect.
You can change the key in the Admin under System > Other Settings > Manage Encryption Key. Back up app/etc/env.php and the database first, and test on staging: the change re-encrypts stored values, and extensions that store their own encrypted data may need attention.
Step 5: Add a WAF layer
A web application firewall buys time between disclosure and patching. Sansec reports its Shield rules have blocked StyleSmuggler attempts since 5 September, and that Cloudflare and Imperva released rules too. For Adobe Commerce on Cloud, Sansec describes Fastly VCL snippets Adobe deployed as a virtual patch.
A WAF does not replace the hotfix. Attackers adjust payloads, and rules only catch what they were written for.
Mage-OS users
Mage-OS published 3.5.0 as an emergency security release on 8 September 2026. It ports Adobe’s StyleSmuggler hotfix with extra hardening and includes the APSB26-138 September isolated patch. Mage-OS only patches its latest release branch, so upgrade to 3.5.0 or later, then follow the same compromise checks and credential rotation.
Hardening after the incident
- Subscribe to Adobe security bulletins and plan to apply monthly patches within days.
- Block PHP execution in
pub/mediaandvarat the web server level. - Run file integrity monitoring on core and
vendor/directories. - Restrict outbound traffic from web nodes to what the store actually needs.
- If you are on 2.4.4 or 2.4.5, start an upgrade: these lines are close to the end of Adobe’s security fixes.
Frequently asked questions
Is Magento Open Source affected, or only Adobe Commerce?
Both. Adobe’s APSB26-146 announcement lists Magento Open Source 2.4.4 through 2.4.9, Adobe Commerce 2.4.4 through 2.4.9 and Adobe Commerce B2B 1.3.3 through 1.5.3.
If I applied the September APSB26-138 patch, am I protected?
No. Adobe states the CVE-2026-75650 hotfix is not included in the September isolated patch. You need both VULN-39341 and the APSB26-138 update.
Do I really need to rotate the encryption key?
Yes. An attacker with code execution can read app/etc/env.php, which holds the key and database credentials. Adobe’s guidance requires rotating the key and every credential it protected.
We patched quickly. Can we skip the forensic checks?
Exploitation started on 4 September, before any patch existed. Unless your store sat behind a WAF rule from day one, checking for indicators is the only way to know.
Need StyleSmuggler patched and checked today?
MageBooster can apply the hotfix and September patch, review your store for compromise indicators and handle credential rotation with your team.
Sources
- Sansec: StyleSmuggler, Magento and Adobe Commerce 0-day RCE (CVE-2026-75650)
- Adobe Experience League: Critical security update for Adobe Commerce (APSB26-146)
- Adobe Experience League: Security update available for Adobe Commerce, APSB26-138
- CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog (8 September 2026)
- Mage-OS releases
- Tenable: StyleSmuggler (CVE-2026-75650) FAQ
- BleepingComputer: Adobe fixes critical Magento zero-day exploited to backdoor servers





