Executive Summary
StyleSmuggler (CVE-2026-75650) is a critical remote code execution (RCE) zero-day vulnerability in Adobe Commerce and Magento Open Source that carries a CVSSv3 score of 10.0. Active exploitation was observed starting September 4, 2026, three days before Adobe released a hotfix. The vulnerability allows unauthenticated attackers to execute arbitrary code by exploiting a flaw in how the platform's template engine processes style properties.
Technically, the attack involves injecting malicious PHP code via template style properties, which is then written to disk and executed when the "Payment Transaction Failed Reminder" notification is rendered. Observed post-exploitation activity includes the deployment of persistent Linux implants masquerading as kernel threads and the placement of PHP web shells in product image caches.
This threat poses a severe risk to e-commerce operations, potentially leading to complete server takeover, data theft, and financial fraud. While a hotfix (VULN-39341) is now available, organizations that were active during the zero-day window must perform thorough incident response, as patching alone does not remediate an existing compromise.
