CVE Tools
Back to feed
Exploited in the wild Adobe Commerce Sansec ransomware Magento Open Source Adobe

Хакеры атаковали уязвимость StyleSmuggler в Magento и Adobe Commerce

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Security researchers at Sansec have disclosed that attackers are actively exploiting StyleSmuggler, a critical flaw identified as CVE-2026-75650 with a CVSS score of 10.0, in Magento Open Source and Adobe Commerce. This vulnerability enables unauthenticated remote code execution on the server by abusing the template engine to inject malicious PHP into system logs.

Affected versions include Adobe Commerce 2.4.4 through 2.4.9 and Magento Open Source 2.4.6 through 2.4.9. Following the confirmation of active attacks, Adobe released an emergency patch on September 8, 2026. Compromised servers typically exhibit a Rust-based backdoor disguised as legitimate Linux processes such as kworker, fc-cache, or chronyd.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store