Dev iconDevSep 18, 2026 ~3 min source read

How CVE-2026-75650 (StyleSmuggler) Used Magento’s Payment-Failure Email to Execute Code

A template-engine weakness in Adobe Commerce and Magento Open Source let unauthenticated attackers inject and execute PHP by poisoning data rendered in the “Payment Transaction Failed Reminder” email. Patching stops new exploitation but does not remove implants placed earlier.

When the Payment-Failure Email Is the Exploit: Inside the Magento Template Rendering Chain of CVE-2026-75650

Share this story

Send the public story page.

Useful takeaways from this story.

Attackers placed crafted data in Magento records (error reports, payment transactions) and triggered the payment-failure email to get the template engine to execute PHP.

Applying the hotfix prevents fresh exploitation but compromised stores require investigation and cleanup: check pub/media, running processes, network egress, and rotate keys and credentials.

Practical detection: a burst of payment-failed reminder emails without matching failed orders is an early indicator of exploitation.

# What happened CVE-2026-75650 (StyleSmuggler) is a template-engine vulnerability in Adobe Commerce and Magento Open Source that allowed unauthenticated remote code execution. The flaw affects versions up through the August 2026 builds listed for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Adobe published an emergency hotfix (VULN-39341, advisory APSB26-146) on 7 September 2026 after exploitation was observed beginning 4 September 2026. Adobe gave the vulnerability a CVSS score of 10.0.

# How the exploit chain works The exploit uses Magento's own template rendering path for transactional emails. Steps observed in public analyses and proof-of-concept repositories:

  • The attacker injects crafted, poisoned data into places where Magento saves its own records, such as error reports and payment transaction entries.
  • The attacker triggers the built-in "Payment Transaction Failed Reminder" email template.
  • When the template engine renders the email, the poisoned data is processed without adequate neutralization, allowing object injection into Magento's dependency-injection container.
  • The object-injection chain results in the processed data being evaluated as PHP code and executed with the web server's privileges.

Observed payloads included a Rust backdoor disguised as kernel-like processes, network activity over UDP 123 masquerading as NTP, and small PHP web shells written into media directories.

# Why this matters operationally Transactional email rendering is not inert formatting. In this case, rendering an automated internal email was used as the execution trigger. The exploit requires no user interaction and no authentication, which increases the practical attack surface for exposed stores.

Patching removes the vulnerability going forward but does not remove implants or active backdoors installed during the window of exploitation (4–7 September 2026). Stores patched after being compromised remained unsafe until cleaned.

# Immediate steps for teams

  • Apply Adobe's emergency hotfix (VULN-39341) if not already installed. The August 2026 monthly patch did not mitigate this issue.
  • Treat a sudden spike of "payment failed" reminder emails without matching failed orders as a strong sign of exploitation.
  • Inspect pub/media for unexpected PHP files and web shells.
  • Check running processes for names imitating kernel threads or common services (for example processes named like kernel threads, fc-cache, chronyd) and look for suspicious UDP 123 egress that could indicate a disguised Rust backdoor communicating.
  • Rotate secrets in this order: encryption keys first, then admin passwords, API tokens (REST, GraphQL, SOAP), payment gateway credentials, database accounts, and SSH keys.
  • Run a targeted scanner such as Sansec's eComscan to detect the observed Rust backdoor and secondary web shells.

# Longer-term and version considerations

# References and signals to watch for

  • Indicators: bursts of payment-failed reminder emails without failed orders, unexpected PHP files in pub/media, processes mimicking system services, and UDP 123 egress.

Use these detection signals and the cleanup checklist to respond if a store was active during the 4–7 September exploitation window.

More context around this story.

The Wider Adobe Patch Wave Behind CVE-2026-75650
Dev iconDevSep 19, 2026

The Wider Adobe Patch Wave Behind CVE-2026-75650

The Wider Adobe Patch Wave Behind CVE-2026-75650 CVE-2026-75650 is the entry in CERT-In's CIVN-2026-0458 that demands immediate action, but it is not the only vulnerability in the advisory. Understanding the surrounding patch wave helps teams sequence the work and avoid treating the whole document as a single, undiffer

5 Best Odoo Magento 2 Connectors in 2026
Webkul iconWebkulSep 29, 2026

5 Best Odoo Magento 2 Connectors in 2026

Managing Magento 2 storefront data and Odoo ERP operations separately can lead to repeated manual data entry and synchronization work. Odoo Magento 2 Connector connects both platforms to synchronize products, orders, customers, inventory, invoices, and shipments. This guide compares Webkul, VentorTech, Emipro, Odoo IN,

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app