132,158 Magento Stores Found Exposed During StyleSmuggler Vulnerability Window
A ZoomEye scan conducted on 19 September 2026 identified 132,158 publicly observable Adobe Commerce and Magento Open Source deployments, providing a population estimate for stores potentially exposed to CVE-2026-75650, known as StyleSmuggler. The vulnerability was actively exploited from 4 September 2026, three days before Adobe released hotfix VULN-39341 on 7 September. The United States hosts the largest share at 46.6% of the top-10 country breakdown, with Germany and the United Kingdom following, consistent with where security firm Sansec observed exploitation activity. Notably, over 4,200 services were detected on cPanel-associated ports, indicating shared-hosting deployments that typically patch slowest and lack in-house incident-response capability — the segment the StyleSmuggler Rust backdoor specifically targets. Researchers caution that the figure represents an observable denominator for risk assessment, not a confirmed victim count, as it excludes stores behind CDNs and does not confirm which deployments ran a vulnerable version during the exposure window.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in