StyleSmuggler: The Magento Zero-Day That Laughs at Patches

StyleSmuggler: The Magento Zero-Day That Laughs at Patches

"Fully patched" used to mean something. Then StyleSmuggler showed up, waltzed past every Magento and Adobe Commerce store running the latest updates, and proved that even the security equivalent of a gym membership doesn't guarantee you'll actually be safe.

A Perfect 10 Nobody Wanted

Dutch security firm Sansec disclosed CVE-2026-75650 on September 5, 2026, after catching attackers actively exploiting it in the wild starting September 4. The flaw, nicknamed StyleSmuggler, scores a maximum 10.0 on the CVSS severity scale and lets unauthenticated attackers run arbitrary code on Magento Open Source and Adobe Commerce stores — no login required.

The attack abuses Magento's own template engine, smuggling PHP code injection through something as mundane as a "Payment Transaction Failed Reminder" email. Trigger that template, and the server hands over the keys. Compromised stores got hit with a Rust-based Linux backdoor phoning home for instructions, plus a PHP web shell for good measure.

Patched Doesn't Mean Protected

Here's the part that should worry every online retailer: stores running fully updated 2.4.6-p15 installs with all July and August security patches applied got popped anyway. Adobe pushed an emergency fix on September 7, and CISA gave federal agencies a hard September 11 deadline to remediate.

The lesson buried in that CVSS score isn't "patch faster" — it's that patching alone is a trailing indicator, not a security strategy. If your incident response plan starts with "wait for the vendor's advisory," attackers already had a four-day head start writing to your server.

Zero-days don't care how recently you clicked "update." They care whether anyone's watching in between.

If your e-commerce stack is running on trust and a patch schedule, James and the WTK team can help you build the layered defenses that catch what patches miss — grab our free developer's security checklist for defending against supply-chain attacks.

Source: The Hacker News