# What happened CVE-2026-75650 (StyleSmuggler) is a template-engine vulnerability in Adobe Commerce and Magento Open Source that allowed unauthenticated remote code execution. The flaw affects versions up through the August 2026 builds listed for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Adobe published an emergency hotfix (VULN-39341, advisory APSB26-146) on 7 September 2026 after exploitation was observed beginning 4 September 2026. Adobe gave the vulnerability a CVSS score of 10.0.
# How the exploit chain works The exploit uses Magento's own template rendering path for transactional emails. Steps observed in public analyses and proof-of-concept repositories:
- The attacker injects crafted, poisoned data into places where Magento saves its own records, such as error reports and payment transaction entries.
- The attacker triggers the built-in "Payment Transaction Failed Reminder" email template.
- When the template engine renders the email, the poisoned data is processed without adequate neutralization, allowing object injection into Magento's dependency-injection container.
- The object-injection chain results in the processed data being evaluated as PHP code and executed with the web server's privileges.
Observed payloads included a Rust backdoor disguised as kernel-like processes, network activity over UDP 123 masquerading as NTP, and small PHP web shells written into media directories.
# Why this matters operationally Transactional email rendering is not inert formatting. In this case, rendering an automated internal email was used as the execution trigger. The exploit requires no user interaction and no authentication, which increases the practical attack surface for exposed stores.
Patching removes the vulnerability going forward but does not remove implants or active backdoors installed during the window of exploitation (4–7 September 2026). Stores patched after being compromised remained unsafe until cleaned.
# Immediate steps for teams
- Apply Adobe's emergency hotfix (VULN-39341) if not already installed. The August 2026 monthly patch did not mitigate this issue.
- Treat a sudden spike of "payment failed" reminder emails without matching failed orders as a strong sign of exploitation.
- Inspect pub/media for unexpected PHP files and web shells.
- Check running processes for names imitating kernel threads or common services (for example processes named like kernel threads, fc-cache, chronyd) and look for suspicious UDP 123 egress that could indicate a disguised Rust backdoor communicating.
- Rotate secrets in this order: encryption keys first, then admin passwords, API tokens (REST, GraphQL, SOAP), payment gateway credentials, database accounts, and SSH keys.
- Run a targeted scanner such as Sansec's eComscan to detect the observed Rust backdoor and secondary web shells.
# Longer-term and version considerations
# References and signals to watch for
- Indicators: bursts of payment-failed reminder emails without failed orders, unexpected PHP files in pub/media, processes mimicking system services, and UDP 123 egress.
Use these detection signals and the cleanup checklist to respond if a store was active during the 4–7 September exploitation window.