Is there a problem that needs an urgent fix?Urgent fix?Get emergency help →
Blog

Practical Magento 2 guides on upgrades, security, speed and migration, written by the MageBooster team.

StyleSmuggler (CVE-2026-75650): what Magento merchants must do now

StyleSmuggler is an actively exploited CVSS 10.0 RCE in Magento 2.4.4–2.4.9. How to patch, check for compromise and rotate credentials.
Consultant explaining a plan to a client

In short

StyleSmuggler (CVE-2026-75650, CVSS 10.0) is an unauthenticated remote code execution flaw in Magento 2.4.4 to 2.4.9 that attackers exploited before a fix existed. Apply Adobe’s APSB26-146 hotfix (VULN-39341) and the separate APSB26-138 September patch, then assume you may already be compromised: hunt for indicators, rotate your encryption key and every credential it protected, and put a WAF rule in front of the store.

In early September 2026, Magento and Adobe Commerce stores were hit by a zero-day that needed no login, no admin session and no form key. Sansec named it StyleSmuggler. Adobe rated it CVSS 10.0, the highest score possible, and shipped an emergency hotfix three days after the first confirmed attack.

If you run any 2.4.x release from 2.4.4 onward and have not applied the hotfix, treat this as an incident, not routine maintenance. This guide covers what happened, which versions are affected, and the exact steps to patch, investigate and harden your store.

What StyleSmuggler is

CVE-2026-75650 abuses Magento’s email template processing. According to Sansec’s analysis, the attack works in two stages:

  1. The attacker plants PHP code in a file that Magento writes itself, such as an error report under var/report/, using a request to the PayPal transparent response endpoint.
  2. A crafted GraphQL request then smuggles template content through styles properties, which slips past existing template safeguards. The attacker triggers Magento’s standard “Payment Transaction Failed Reminder” email, and the injected code runs while Magento renders that email.

Nobody has to open the email. The code executes server-side during rendering. Sansec observed attackers using this to launch a disguised background process that connects to a command-and-control server and waits for instructions.

Timeline

Date (2026)Event
23 AugustFirst unsuccessful probes observed by Sansec
4 September, 22:20 UTCFirst confirmed exploitation
5 SeptemberSansec publishes its analysis and deploys blocking rules
7 SeptemberAdobe publishes security bulletin APSB26-146 with hotfix VULN-39341
8 SeptemberAdobe’s regular September bulletin APSB26-138 ships; Mage-OS 3.5.0 emergency release; CISA adds CVE-2026-75650 to its Known Exploited Vulnerabilities catalog

Affected versions

Adobe’s APSB26-146 announcement lists these as affected, including the August 2026 releases and earlier:

  • Adobe Commerce 2.4.4 through 2.4.9
  • Adobe Commerce B2B 1.3.3 through 1.5.3
  • Magento Open Source 2.4.4 through 2.4.9

Some third-party write-ups list Magento Open Source from 2.4.6 rather than 2.4.4. Do not rely on that difference: if you run any 2.4.4 or later release, apply the fix.

Releases older than 2.4.4 receive no official patch from Adobe. Sansec reports that a third party has published backports for some older lines, but if you are on 2.4.3 or earlier, the honest answer is that you are running unsupported software with a known critical exploit, and an upgrade plan should start now.

Step 1: Apply the APSB26-146 hotfix

The fix is hotfix VULN-39341, distributed as VULN-39341-composer-patches.zip through Adobe’s announcement and repo.magento.com. Adobe also provides version-specific patch files for some release lines, so download the one that matches your exact version.

Apply it on staging first if you can do so within hours, not days. Given active exploitation, a short maintenance window on production is a reasonable trade-off.

# check your exact version first
bin/magento --version
composer show magento/product-community-edition 2>/dev/null || composer show magento/product-enterprise-edition

# after unzipping, apply the composer patch from the project root
git apply VULN-39341_composer.patch   # or: patch -p1 < VULN-39341_composer.patch

bin/magento setup:di:compile
bin/magento cache:flush

Follow Adobe’s “How to apply a composer patch provided by Adobe” article for your setup. On Adobe Commerce on Cloud, add the patch to the m2-hotfixes directory and redeploy. Sansec suggests confirming the patch status with the Quality Patches Tool:

vendor/bin/magento-patches -n status | grep "39341\|Status"

Step 2: Apply the September APSB26-138 patch as well

APSB26-138, released 8 September 2026, is the regular monthly security update. It fixes eight vulnerabilities, all rated Critical, including stored XSS, incorrect authorization and path traversal issues. Adobe stated it was not aware of exploits in the wild for those issues at release.

The important detail: the StyleSmuggler hotfix is not included in the September isolated patch file. Adobe’s knowledge base article says to apply both. Isolated September patches are available for 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 and 2.4.4-p18.

Step 3: Check for signs of compromise

Exploitation began three days before a patch existed. Patching closes the door but does not remove anyone already inside. Sansec published indicators you can check today.

Processes and cron

Look for background processes posing as system tools, for example names like [kworker/u:8:0], fc-cache or chronyd running as your web user, and for unfamiliar crontab entries.

ps -eo user,pid,ppid,cmd | grep -E "fc-cache|chronyd|kworker" | grep -v grep
crontab -l -u www-data   # use your PHP/web user

Files

ls -la ~/.cache/fontconfig/ 2>/dev/null
ls -la /tmp | grep -E "\.fc-|\.chrony-"
find pub/media -name "*.php" -mtime -45
find pub/media/catalog/product/cache -path "*ss_*" -name "sync_*.php"

Any PHP file under pub/media is a red flag. That directory should only hold assets.

Logs and network

  • Search var/log/exception.log for Laminas\Loader\Exception\InvalidArgumentException.
  • Look for bursts of “Payment Transaction Failed” emails in your mail logs or transactional email provider.
  • Review web server logs for requests to /paypal/transparent/response/ with unusual query strings and GraphQL POSTs containing styles.
  • Check outbound connections from web nodes to the command-and-control addresses Sansec lists, such as 99.84.67.186.

Sansec’s eComscan scanner has detection for StyleSmuggler implants. If you find anything, isolate the server, preserve logs and file timestamps for forensics, and rebuild from a known-clean source rather than deleting files one by one.

Step 4: Rotate the encryption key and every credential

This is the step most teams skip, and Adobe is explicit about it. After applying the hotfix, rotate:

  1. The Magento encryption key
  2. All admin passwords
  3. REST, SOAP and GraphQL integration tokens
  4. OAuth secrets for third-party apps
  5. Payment gateway credentials, at the provider
  6. Database and Fastly credentials
  7. SSH and deploy keys, plus service accounts
  8. Third-party API keys for shipping, tax and extensions

Adobe notes that rotating the encryption key alone does not invalidate credentials that may already have leaked. Each secret has to be changed at its source. On Adobe Commerce on Cloud, rerun the deployment after updating credentials so new database credentials take effect.

You can change the key in the Admin under System > Other Settings > Manage Encryption Key. Back up app/etc/env.php and the database first, and test on staging: the change re-encrypts stored values, and extensions that store their own encrypted data may need attention.

Step 5: Add a WAF layer

A web application firewall buys time between disclosure and patching. Sansec reports its Shield rules have blocked StyleSmuggler attempts since 5 September, and that Cloudflare and Imperva released rules too. For Adobe Commerce on Cloud, Sansec describes Fastly VCL snippets Adobe deployed as a virtual patch.

A WAF does not replace the hotfix. Attackers adjust payloads, and rules only catch what they were written for.

Mage-OS users

Mage-OS published 3.5.0 as an emergency security release on 8 September 2026. It ports Adobe’s StyleSmuggler hotfix with extra hardening and includes the APSB26-138 September isolated patch. Mage-OS only patches its latest release branch, so upgrade to 3.5.0 or later, then follow the same compromise checks and credential rotation.

Hardening after the incident

  • Subscribe to Adobe security bulletins and plan to apply monthly patches within days.
  • Block PHP execution in pub/media and var at the web server level.
  • Run file integrity monitoring on core and vendor/ directories.
  • Restrict outbound traffic from web nodes to what the store actually needs.
  • If you are on 2.4.4 or 2.4.5, start an upgrade: these lines are close to the end of Adobe’s security fixes.

Frequently asked questions

Is Magento Open Source affected, or only Adobe Commerce?

Both. Adobe’s APSB26-146 announcement lists Magento Open Source 2.4.4 through 2.4.9, Adobe Commerce 2.4.4 through 2.4.9 and Adobe Commerce B2B 1.3.3 through 1.5.3.

If I applied the September APSB26-138 patch, am I protected?

No. Adobe states the CVE-2026-75650 hotfix is not included in the September isolated patch. You need both VULN-39341 and the APSB26-138 update.

Do I really need to rotate the encryption key?

Yes. An attacker with code execution can read app/etc/env.php, which holds the key and database credentials. Adobe’s guidance requires rotating the key and every credential it protected.

We patched quickly. Can we skip the forensic checks?

Exploitation started on 4 September, before any patch existed. Unless your store sat behind a WAF rule from day one, checking for indicators is the only way to know.

Need StyleSmuggler patched and checked today?

MageBooster can apply the hotfix and September patch, review your store for compromise indicators and handle credential rotation with your team.

Talk to a Magento expert

Sources

Free Site Audit

Send your store details. We check speed, security and extensions, then reply with three quick wins within 3 working days.

Let's talk

Get a quote

Tell us about your store and we’ll reply within one working day. Prefer to chat? Say hello from WhatsApp