TL;DR
what: Adobe patched CVE-2026-75650, a CVSS 10.0 unauthenticated remote code execution flaw in Adobe Commerce and Magento Open Source that Sansec codenamed StyleSmuggler and observed being exploited as a zero-day from September 4, 2026.
impact: Attackers get code execution as the web server with no credentials, and observed payloads include a Rust based Linux backdoor that beacons to an external server plus a PHP dropper that writes an arbitrary-PHP web shell on the checkout host.
fix: Apply Adobe's VULN-39341 hotfix from repo.magento.com and rotate your encryption keys, which Adobe lists as a required second step, not an optional one.
who: Every Adobe Commerce 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.4 through 2.4.9 install running the 2026-aug builds or earlier.










