Adobe has released an emergency security update for Adobe Commerce and Magento Open Source after confirming that a critical vulnerability is being actively exploited in the wild.
The flaw, tracked as CVE-2026-75650 and dubbed StyleSmuggler by security researchers at Sansec, carries the maximum CVSS score of 10.0. Adobe says successful exploitation can lead to arbitrary code execution and does not require authentication.
What happened
Adobe published security bulletin APSB26-146 on September 7, 2026, warning customers that CVE-2026-75650 is already being exploited. The company released a hotfix and assigned the update its highest priority rating.
According to Adobe, affected releases include Adobe Commerce versions across the 2.4.4 through 2.4.9 branches, along with Magento Open Source 2.4.6, 2.4.7, 2.4.8 and 2.4.9 releases up to the August 2026 updates. Adobe Commerce B2B versions are also affected.
Security firm Sansec says it first observed exploitation on September 4 and reproduced the unauthenticated attack chain on clean Magento installations. The researchers later observed a second, unrelated attacker deploying a PHP web shell, suggesting the vulnerability is no longer limited to a single campaign.
Why this matters
This is more serious than a routine software patch. Adobe Commerce and Magento power online stores, so a vulnerability that allows remote code execution without credentials can give attackers a path to compromise store infrastructure, establish persistence and potentially access sensitive business or customer data.
Sansec says attackers have been seen disguising malicious background processes using names that resemble legitimate Linux system processes. The firm also noted that unexpected bursts of failed-payment reminder emails can be a warning sign, although legitimate failed payments can produce the same messages.
What store owners should do now
Adobe recommends customers install the official hotfix for CVE-2026-75650 immediately. Because attacks began before the patch became available, administrators should also investigate whether systems were already compromised rather than assuming installation of the fix alone resolves every risk.
Store operators should review Adobe’s official bulletin and hotfix instructions, check systems for indicators of compromise, review suspicious processes and files, and consider rotating administrative or Magento credentials if there is evidence of intrusion.
Sansec has also published technical indicators and mitigation guidance for administrators investigating StyleSmuggler activity.
What it means for readers
If you run an Adobe Commerce or Magento store, this should be treated as an urgent security update rather than something to leave for the next maintenance window. The combination of a maximum severity score, no authentication requirement and confirmed exploitation makes this one of the highest-priority ecommerce security issues currently in circulation.
For shoppers, there is no reason to panic simply because a store uses Magento. But businesses that delay patching or fail to check for prior compromise could expose themselves and their customers to unnecessary risk.
Sources: Adobe Security Bulletin APSB26-146; Sansec StyleSmuggler research.

