CVE-2026-75650, dubbed StyleSmuggler, is a critical (CVSS 10.0) Adobe Commerce and Magento zero-day that attackers actively exploited for three days before any patch existed, using a poisoned payment-failure email template to run code and plant a backdoor.
Read the full story: Magento Zero-Day StyleSmuggler Hit Stores Before Adobe Patched →
Transcript
Adobe Commerce and Magento stores got hacked for three straight days before a patch even existed. Security firm Sansec caught it: attackers injected malicious code through a payment failure email template. Fail a payment on purpose, and the store's own email system would run your code. Adobe rushed out an emergency fix, APSB26-146, but patching doesn't undo what already happened. If your store was exposed between September 4th and 7th, attackers may have already grabbed your encryption keys.
Adobe's own guidance says rotate every key, patched or not. And the backdoor they planted disguises its traffic as a normal time-sync request, hiding in plain sight. Patch first. Rotate keys next.