Forum Discussion
StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
On September 5, 2026, the Sansec Forensics Team published research detailing an actively exploited zero-day vulnerability in Magento and Adobe Commerce that it named StyleSmuggler. StyleSmuggler, also known as CVE-2026-75650 is a remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Successful exploitation grants an unauthenticated attacker the ability to execute arbitrary code on a vulnerable server.
CVE-2026-75650 carries a CVSSv3 score of 10.0, the highest possible rating. Additionally, its scope is changed, meaning exploitation can impact resources beyond the vulnerable component itself.
|
CVE |
Description |
CVSSv3 |
|
CVE-2026-75650 |
Adobe Commerce and Magento Open Source Remote Code Execution |
10.0 |
On September 7, 2026, Adobe released Hotfix VULN-39341 to address CVE-2026-75650. Additional details can be found in Adobe's security bulletin APSB26-146.
Adobe also recommends rotating the encryption key and all credentials it protects following a compromise, including admin passwords, REST, SOAP, and GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH and deploy keys, and extension API keys.
For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.