Critical Magento Flaw CVE-2026-75650 Exploited; Over 132,000 Instances Exposed
A template injection vulnerability dubbed StyleSmuggler (CVE-2026-75650) was found to affect Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9, including installs that had applied earlier patches. Active exploitation was confirmed on 4 September 2026, prompting Adobe to release hotfix VULN-39341 on 7 September, with CISA adding it to its Known Exploited Vulnerabilities catalogue the following day. Fingerprint-based scanning identified approximately 132,707 potentially affected Magento instances, far outpacing title-based queries which returned only 5,314 results, as most merchants replace default platform branding. The flaw is triggered through a payment failure email template rendering path, and successful attacks have been observed installing a Rust-based backdoor and, in some cases, a PHP web shell. Stores compromised during the three-day window before the hotfix remain at risk even after patching, requiring manual checks for rogue files, anomalous processes, and suspicious outbound traffic.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in