StyleSmuggler Zero-Day Remote Code Execution in Magento
Score: 7/10

StyleSmuggler Zero-Day Remote Code Execution in Magento

StyleSmuggler is an unauthenticated remote code execution vulnerability (CVE-2026-75650) in Adobe Commerce and Magento exploited to deploy persistent implants and web shells.

Executive Summary

StyleSmuggler (CVE-2026-75650) is a critical remote code execution (RCE) zero-day vulnerability in Adobe Commerce and Magento Open Source that carries a CVSSv3 score of 10.0. Active exploitation was observed starting September 4, 2026, three days before Adobe released a hotfix. The vulnerability allows unauthenticated attackers to execute arbitrary code by exploiting a flaw in how the platform's template engine processes style properties.

Technically, the attack involves injecting malicious PHP code via template style properties, which is then written to disk and executed when the "Payment Transaction Failed Reminder" notification is rendered. Observed post-exploitation activity includes the deployment of persistent Linux implants masquerading as kernel threads and the placement of PHP web shells in product image caches.

This threat poses a severe risk to e-commerce operations, potentially leading to complete server takeover, data theft, and financial fraud. While a hotfix (VULN-39341) is now available, organizations that were active during the zero-day window must perform thorough incident response, as patching alone does not remediate an existing compromise.

Key Details

Threat Name

StyleSmuggler (CVE-2026-75650)

Affects

Adobe Commerce 2.4.4 - 2.4.9, Adobe Commerce B2B 1.3.3 - 1.5.3, Magento Open Source 2.4.6 - 2.4.9, Adobe Commerce, Magento, Microsoft Products

Adversary

—

Malware/Tools

StyleSmuggler, PHP web shell

Report Score

7out of 10
Quality Score
Good
IOC Quality6
TTP Details9
Detection Guidance5
Enterprise Relevance9
Clarity & Structure8
Technical Depth7

Sources