"Fully patched" used to mean something. Then StyleSmuggler showed up, waltzed past every Magento and Adobe Commerce store running the latest updates, and proved that even the security equivalent of a gym membership doesn't guarantee you'll actually be safe.
A Perfect 10 Nobody Wanted
Dutch security firm Sansec disclosed CVE-2026-75650 on September 5, 2026, after catching attackers actively exploiting it in the wild starting September 4. The flaw, nicknamed StyleSmuggler, scores a maximum 10.0 on the CVSS severity scale and lets unauthenticated attackers run arbitrary code on Magento Open Source and Adobe Commerce stores — no login required.
The attack abuses Magento's own template engine, smuggling PHP code injection through something as mundane as a "Payment Transaction Failed Reminder" email. Trigger that template, and the server hands over the keys. Compromised stores got hit with a Rust-based Linux backdoor phoning home for instructions, plus a PHP web shell for good measure.
Patched Doesn't Mean Protected
Here's the part that should worry every online retailer: stores running fully updated 2.4.6-p15 installs with all July and August security patches applied got popped anyway. Adobe pushed an emergency fix on September 7, and CISA gave federal agencies a hard September 11 deadline to remediate.
The lesson buried in that CVSS score isn't "patch faster" — it's that patching alone is a trailing indicator, not a security strategy. If your incident response plan starts with "wait for the vendor's advisory," attackers already had a four-day head start writing to your server.
Zero-days don't care how recently you clicked "update." They care whether anyone's watching in between.
If your e-commerce stack is running on trust and a patch schedule, James and the WTK team can help you build the layered defenses that catch what patches miss — grab our free developer's security checklist for defending against supply-chain attacks.
Source: The Hacker News