ADOBE has released security patches for Adobe Commerce and Magento Open Source to fix a critical, actively exploited vulnerability tracked as CVE-2026-75650 (CVSS 10.0), codenamed StyleSmuggler by Sansec. Exploitation in the wild began around 4 September 2026. Adobe states the flaw could allow arbitrary code execution and that CVE-2026-75650 has been used against affected Adobe Commerce merchants.
The vulnerability stems from PHP code injection via Magento’s template system, which can be triggered to generate a “Payment Transaction Failed Reminder” email and, in the process, execute remote code on the server.
Affected products and versions include: Adobe Commerce 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier, 2.4.5-2026-aug and earlier, 2.4.4-2026-aug and earlier; Adobe Commerce B2B 1.5.3-2026-aug and earlier, 1.5.2-2026-aug and earlier, 1.4.2-2026-aug and earlier, 1.3.4-2026-aug and earlier, 1.3.3-2026-aug and earlier; Magento Open Source 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier.
Adobe instructs applying the VULN-39341 patch (appropriate to your version) and rotating encryption keys. Evidence from the Dutch security firm Disrex notes a Magento server being compromised within 50 minutes of the first confirmed StyleSmuggler exploitation on 4 September 2026, and prior reporting cited threat actors deploying a Rust-based Linux backdoor and a PHP dropper delivering a web shell. The patch is available via repo.magento[.]com/patch/VULN-39341-composer-patches[.]zip.