Adobe patches maximum-severity Commerce flaw after attackers exploit it for days
A critical, unauthenticated code-execution flaw in Adobe Commerce and Magento was actively exploited for three days before a fix arrived, prompting CISA to order federal agencies to patch by Thursday.

Adobe has patched a maximum-severity security flaw in Adobe Commerce and Magento Open Source after attackers spent three days quietly breaking into online stores through it, planting backdoors that let them return to compromised servers at will. The vulnerability, tracked as CVE-2026-75650 and nicknamed "StyleSmuggler" by the researchers who found it, carries a CVSS score of 10.0, the highest possible rating, and the Cybersecurity and Infrastructure Security Agency has ordered federal agencies to finish patching it by Thursday.
The flaw allowed an unauthenticated attacker — someone with no login credentials at all — to run arbitrary code on any exposed Adobe Commerce or Magento installation simply by triggering a routine, automated email.
What happened
According to the e-commerce security firm Sansec, active exploitation began on September 4, 2026, three days before Adobe shipped a fix. The attack abuses Magento's template-processing engine through the platform's "Payment Transaction Failed Reminder" feature, a standard notification email the software generates automatically. By smuggling malicious code into fields the template engine renders, an attacker could get the server to execute PHP commands without ever logging in.
Adobe confirmed the exploitation in its own advisory, stating plainly that it is "aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants," according to the company's Adobe Commerce security announcement. The company released Hotfix VULN-39341 on September 7 to close the hole, three days after the first confirmed attacks.
Once inside, intruders installed persistent malware disguised to blend into normal server activity. Researchers found implants hidden at file paths designed to look like routine desktop-session files, with processes renamed to mimic innocuous system tasks so that a cursory look at a running-process list would not raise alarms. A cron job restarted the malware automatically, initially every five minutes, later adjusted to twice an hour. Separately, the incident response firm Disrex documented a distinct wave of attacks in which intruders planted PHP web shells inside the folders stores use to cache product images — a location administrators rarely inspect.
The vulnerability affects Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9, and Adobe Commerce B2B versions 1.3.3 through 1.5.3 — effectively every supported release as of August 2026, according to Adobe's bulletin and an FAQ published by security firm Tenable. On September 8, CISA added the flaw to its Known Exploited Vulnerabilities catalog alongside two Microsoft Windows privilege-escalation bugs and a flaw in N-able's N-central remote-monitoring software, giving U.S. federal civilian agencies until September 11 to apply the patch under a binding operational directive.
Reporting from The Hacker News put the earliest confirmed exploitation at 10:20 p.m. UTC on September 4, and cited at least one case in which a merchant's server was compromised just 50 minutes after attackers began probing for the flaw. A separate monitoring firm, Previdian, recorded a dozen automated exploitation attempts against decoy systems from IP addresses in China and Romania in the days following disclosure, an indication that the exploit had already spread into commodity attack tooling rather than being confined to a single sophisticated actor.
Who is affected
Adobe Commerce (formerly Magento Commerce) and its open-source counterpart power a substantial share of mid-size and large online retailers worldwide, making the flaw's unauthenticated, no-interaction-required nature especially serious for the e-commerce sector. Because the vulnerability lets an attacker execute code before ever authenticating, every internet-facing store running an unpatched version was exposed regardless of how strong its administrator passwords were or how carefully its staff had been trained against phishing.
Merchants that have already applied the patch are not necessarily in the clear. Adobe and outside researchers are both warning that installing the hotfix alone does not undo whatever an attacker may have already done to a compromised store. Sansec was blunt about the limits of a simple patch-and-move-on response.
"Rotating the encryption key on its own does not invalidate anything an attacker already read," Sansec warned, according to reporting by SecurityWeek.
Adobe's guidance for affected merchants goes well beyond installing the hotfix: the company is advising a full rotation of encryption keys and every credential those keys protect, including administrator passwords, database credentials, payment gateway API keys, OAuth client secrets and SSH keys, along with suspending cron jobs and enabling maintenance mode during remediation. For a mid-size retailer, that list amounts to a full credential reset across nearly every system connected to the storefront.
The episode is not the first time Magento-based stores have been targeted at scale. The platform has been a recurring focus of large, automated skimming campaigns over the years, in which attackers harvest customer payment card data directly from checkout pages rather than simply defacing a site or demanding ransom. What distinguishes StyleSmuggler from many earlier Magento incidents is the absence of any prerequisite — no stolen admin credentials, no vulnerable third-party extension, no social engineering. The flaw sat in code that ships with every standard installation and triggers on a routine automated action, which is part of why security researchers moved quickly to publicize technical details once Adobe's patch was available, hoping to outpace attackers racing to compromise as many unpatched stores as possible before defenders caught up.
Reaction and broader context
The incident response firm Disrex, which documented one of the attack variants independently of Sansec, described the flaw in stark terms: the vulnerability "turns Magento's own template-processing and dependency-injection code into an unauthenticated remote-code-execution chain," the firm said, as reported by The Hacker News. That framing underscores what security researchers found most alarming about StyleSmuggler — it did not require a misconfiguration or a weak password to exploit. It weaponized a feature the software was designed to run automatically for every store.
The disclosure lands during an unusually heavy week for enterprise security teams. Adobe's Commerce fix arrived as part of a broader September update round that patched more than 170 vulnerabilities across the company's product line, including 107 in Experience Manager, 32 in Acrobat Reader and two critical remote-code-execution bugs in ColdFusion. It also coincided with Microsoft's own September Patch Tuesday release, which separately addressed close to a thousand vulnerabilities including two actively exploited Windows zero-days that CISA added to the same Known Exploited Vulnerabilities catalog entry as the Adobe flaw.
What happens next
For federal agencies, the immediate deadline is September 11 under CISA's binding operational directive, though the agency's advisory notes that all organizations — not just those bound by federal directives — should treat the vulnerability with the same urgency given active, ongoing exploitation. Security firms tracking the flaw expect exploitation attempts to continue rising in the coming days as the technical details behind StyleSmuggler circulate more widely among less sophisticated attackers, a common pattern once a working exploit for an unauthenticated, maximum-severity flaw becomes public.
For individual merchants, the practical next steps extend well past applying Adobe's hotfix. Security researchers are urging affected stores to assume compromise until proven otherwise, conduct forensic reviews of server logs stretching back to September 4, and complete full credential rotation before considering an affected store secure again. Adobe has not said how many stores were compromised in total, and given the automated, low-effort nature of the exploit, the full scope of the incident may not be clear for some time.
Adobe Commerce Knowledge Base — Urgent Action Required: Critical Security Update (APSB26-146)
CISA — CISA Adds Four Known Exploited Vulnerabilities to Catalog
The Hacker News — Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
SecurityWeek — Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Google signs 22-year nuclear power deal with Finland's Fortum, commits €13 billion to AI data centers

US intelligence agencies accuse six Chinese AI firms of industrial-scale theft of American model capabilities

Mistral Raises €3 Billion in Europe's Largest Tech Funding Round, Led by Samsung
