StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero
StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.
Key takeaways
- CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.
- Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different attack campaigns.
- Adobe released Hotfix VULN-39341 on September 7, 2026, and Tenable detection plugins will be published as they become available.
Background
Tenable's Research Special Operations Team (RSO) has compiled this blog to answer Frequently Asked Questions (FAQ) regarding CVE-2026-75650, a zero-day remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that has been actively exploited in the wild.
FAQ
When was CVE-2026-75650 first disclosed?
On September 5, 2026, the Sansec Forensics Team published research detailing an actively exploited zero-day vulnerability in Magento and Adobe Commerce that it named StyleSmuggler.
What is CVE-2026-75650?
CVE-2026-75650 is a remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Successful exploitation grants an unauthenticated attacker the ability to execute arbitrary code on a vulnerable server. CVE-2026-75650 carries a CVSSv3 score of 10.0, the highest possible rating. Additionally, its scope is changed, meaning exploitation can impact resources beyond the vulnerable component itself.
| CVE | Description | CVSSv3 |
|---|---|---|
| CVE-2026-75650 | Adobe Commerce and Magento Open Source Remote Code Execution | 10.0 |
The following products and versions are affected:
| Product | Affected versions |
|---|---|
| Adobe Commerce | 2.4.4 through 2.4.9 |
| Adobe Commerce B2B | 1.3.3 through 1.5.3 |
| Magento Open Source | 2.4.6 through 2.4.9 |
How does StyleSmuggler work?
StyleSmuggler exploits a flaw in how Magento's template engine processes style-related properties. An attacker crafts a malicious payload containing PHP code and injects it through the styles properties within the template system. Magento writes this attacker-controlled content to disk as part of its normal operations. The injected code is then executed when the platform renders a transactional email template, specifically the “Payment Transaction Failed Reminder” notification. Because this injection path does not sit behind any authentication gate, a remote attacker can trigger it without credentials, and the technique works regardless of which session storage backend is configured.
Once a server is compromised, the attacker deploys a persistent implant. The malware binary is installed at ~/.local/share/.gvfsd/gvfsd-user and masquerades as a Linux kernel thread using the process name [kworker/u:8:0]. It also disguises itself using the process names fc-cache and chronyd, both legitimate system utilities. A cron job restarts the implant every five minutes. Later variants updated the cron interval to twice an hour, and the malware supports both x86-64 and arm64 architectures.
Is CVE-2026-75650 being exploited in the wild?
Yes. Active exploitation of CVE-2026-75650 began on September 4, 2026 according to Sansec. Multiple victim stores have been confirmed across different attack campaigns. Disrex, an incident response firm, had first-hand experience with at least two compromised stores.
Historical exploitation of Adobe Commerce and Magento
Adobe Commerce and its open-source counterpart, Magento, have been recurring targets for attackers. Three prior Adobe Commerce and Magento vulnerabilities have been added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog.
| CVE | Description | KEV date added |
|---|---|---|
| CVE-2025-54236 | Improper input validation, account takeover via REST API (“SessionReaper”) | 2025-10-24 |
| CVE-2024-34102 | XXE restriction bypass leading to remote code execution (“CosmicSting”) | 2024-07-17 |
| CVE-2022-24086 | Improper input validation leading to arbitrary code execution | 2022-02-15 |
CVE-2026-75650 has not yet been added to CISA KEV as of September 8, 2026. There is no CISA Emergency Directive or Alert associated with this vulnerability at this time.
Which threat actors are exploiting CVE-2026-75650?
As of September 8, 2026, there is no public attribution linking the exploitation of CVE-2026-75650 to a specific threat actor or group. Sansec documented activity from at least two distinct operators on the same victim stores: the original group deploying the persistent implant, and a second unrelated attacker dropping a PHP web shell into the product image cache. The techniques and tooling differ significantly between the two, and Sansec treats them as separate campaigns.
Is there a proof-of-concept (PoC) available for CVE-2026-75650?
At the time this blog post was published on September 8, there is no standalone public proof-of-concept for CVE-2026-75650.
Are there indicators of compromise (IoCs) for CVE-2026-75650?
Yes. Sansec published indicators of compromise alongside its StyleSmuggler research. The full IoC list can be found in Sansec's blog.
Has Tenable Research classified CVE-2026-75650 as part of Vulnerability Watch?
Yes. Tenable Research has classified CVE-2026-75650 as a Vulnerability of Interest (VOI) as part of Vulnerability Watch.
Are patches available for CVE-2026-75650?
On September 7, 2026, Adobe released Hotfix VULN-39341 to address CVE-2026-75650. Additional details can be found in Adobe's security bulletin APSB26-146.
Adobe also recommends rotating the encryption key and all credentials it protects following a compromise, including admin passwords, REST, SOAP, and GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH and deploy keys, and extension API keys.
At the time exploitation was first observed on September 4, no vendor patch existed. Patching alone does not remediate an existing compromise. Stores that were active during the three-day window before the hotfix require incident response in addition to applying the fix.
Has Tenable released detection coverage for CVE-2026-75650?
A list of Tenable detection plugins for CVE-2026-75650 will be available on the CVE page as they are released. This link will display all available plugins for this vulnerability, including upcoming plugins in our Plugins Pipeline.
Get more information
- Sansec: StyleSmuggler 0day Research
- Adobe Security Bulletin APSB26-146
- Disrex: StyleSmuggler incident response and mitigations
Join Tenable's Research Special Operations (RSO) Team on the Tenable Community.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Learn more
- Exposure Management
- Vulnerability Management
Tenable One
Request a demo
The world’s leading AI-powered exposure management platform.
Thank You
Thank you for your interest in Tenable One.
A representative will be in touch soon.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.