Critical Magento RCE Flaw CVE-2026-75650 Exploited via Payment-Failure Emails
Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9 are affected by an unauthenticated remote code execution vulnerability, CVE-2026-75650, which exploits the platform's payment-failure email rendering engine. Dutch security firm Sansec, which dubbed the campaign StyleSmuggler, recorded active exploitation beginning September 4, 2026, with CISA adding the flaw to its Known Exploited Vulnerabilities catalog on September 8. Adobe issued emergency hotfix VULN-39341 on September 7 under advisory APSB26-146, noting that stores already patched with the August 2026 monthly update remained exposed. Attackers inject malicious data into error reports and payment records, then trigger the standard payment-failure reminder email, causing the template engine to execute arbitrary PHP code with web-server privileges. Observed post-compromise payloads include a Rust backdoor disguised as system processes and PHP web shells, with remediation requiring the hotfix, credential rotation, and a targeted malware scan.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in