Security1 publisher2 min readPublished
CVE-2026-75650 scores a flat 10.0 and was already in use on September 4. Adobe's hotfix comes paired with encryption key rotation, and Sansec's Rust backdoor findings matter more than the score does.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The chain runs without a login. Disrex, the Netherlands-based e-commerce development platform, describes StyleSmuggler as turning Magento's own template-processing and dependency-injection code into an unauthenticated remote-code-execution chain [9]. The injection point is routine merchant plumbing: PHP that executes while Magento's template system builds a "Payment Transaction Failed Reminder" email [4].
Adobe's remediation instruction pairs a patch with a key rotation. Merchants are told to apply the VULN-39341 patch, distributed as a composer patches archive from repo.magento.com, and to rotate their encryption keys [6]. No reasoning for the rotation appears in the advisory language Adobe published [6], and the requirement only makes sense if secrets sitting on an affected host are assumed to have been read.
Disrex puts the first confirmed exploitation at 10:20 pm UTC on Friday, September 4 [8][2], which places the compromise of its own managed Magento server at roughly 11:10 pm UTC the same night [1]. Adobe's fix landed on a Monday that the source does not date; the earliest Monday after September 4 is September 7, so the gap between first exploitation and an available patch was three days at minimum and is not on the record beyond that [5].
Previdian's first honeypot hit came three days behind the first confirmed exploitation [3]. That is the shape of a technique moving outward from whoever found it first, and honeypot counts do not measure how many stores were entered.
Scope is wide in version terms and precise in build terms. Adobe lists 15 affected branches [4]: six Adobe Commerce lines from 2.4.4 through 2.4.9, five Commerce B2B lines from 1.3.3 through 1.5.3 and four Magento Open Source lines from 2.4.6 through 2.4.9, each at the 2026-aug build or earlier [5]. A store on any of them that was reachable on September 4 has no version-based grounds to assume it was skipped. Filesystem writes and outbound connections are what answer that question, not the build string alone.
Ranked by verification strength, evidence, and original report placement.
Adobe released security patches on Monday for a maximum-severity flaw affecting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.
The vulnerability is tracked as CVE-2026-75650 with a CVSS score of 10.0 and was codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.
Adobe said the update resolves a critical vulnerability that could result in arbitrary code execution, and that it is aware CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants.
The flaw abuses Magento's template system through PHP code injection to generate a "Payment Transaction Failed Reminder" email, triggering code execution in the process.
Affected versions are Adobe Commerce 2.4.9, 2.4.8, 2.4.7, 2.4.6, 2.4.5 and 2.4.4 at build 2026-aug and earlier; Adobe Commerce B2B 1.5.3, 1.5.2, 1.4.2, 1.3.4 and 1.3.3 at build 2026-aug and earlier; and Magento Open Source 2.4.9, 2.4.8, 2.4.7 and 2.4.6 at build 2026-aug and earlier.
Adobe said merchants must apply the VULN-39341 patch depending on their version and rotate their encryption keys; the hotfix is distributed as a composer patches zip archive from repo.magento.com. The source quotes no explanation from Adobe for the key rotation requirement.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Four named sources, one newsroom
Adobe's advisory is quoted rather than paraphrased, Sansec is credited for the discovery and for the malware it found, Disrex speaks on the record about its own compromised server, and Previdian's telemetry arrives with its chief executive named. That is unusually well-attributed for a same-week vulnerability story. The limit is that all four attributions reach readers through The Hacker News alone, so the timestamps and counts come straight from primary parties but have been checked by no second newsroom.
Confirmed exploitation, no denominator
Attacks are documented rather than hypothesised: Adobe says merchants are being targeted, Disrex lost a managed store within an hour of the first confirmed hit, and Previdian's sensors caught a dozen tries. The missing piece is scale. Nothing in the reporting counts how many stores run a 2026-aug or earlier build, how many have applied VULN-39341, or how many compromises exist beyond the one Disrex describes.
Score runs ahead of observed volume
A flat 10.0 and "maximum severity" describe what the flaw permits: code execution with no login, through an email the platform generates itself. The activity actually reported is smaller than the number implies, at twelve failed attempts from two addresses plus the single Disrex compromise. Sansec's Rust backdoor and PHP web shell are the more useful detail, because they describe what an attacker installs once inside, and they get less space than the score.
Found by vendors with Magento security to sell
Three of the four parties have commercial standing in exactly this problem: Sansec sells Magento malware detection, Previdian's product is the telemetry it published, and Disrex builds and manages the stores at risk. Disrex's contribution cuts against its own interest, since it consists of admitting one of its servers was taken. Adobe's advisory is the least forthcoming element, pairing a mandatory encryption-key rotation with no account of why keys need rotating.
Solid on the fix, loose on the clock
The version matrix, the hotfix path and the two-step remediation are firm enough to act on this afternoon. The timeline is where it thins: the fix is dated only to "Monday", which bounds the exposure window at three days or more without pinning it, and the only volume figures come from one vendor's honeypots. A second account of the September 4 night would move this materially.
security
Fully patched Magento stores are being backdoored four days ahead of Adobe's next security release5 publishers
security
Exploit attempts hit NetScaler's August auth bypass 15 days after Citrix shipped the fix1 publisher
build
Six MariaDB versions, one real difference: the only reason to leave 10.6 is the July 2026 clock1 publisher
security
Six bugs, one order of operations: Avada's zero-click chain is a same-day patch1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 8, 2026