Download the latest Vulnerability & Exploitation Report

Download now
CVE-2026-75650 StyleSmuggler

CVE-2026-75650 StyleSmuggler: Adobe Commerce & Magento Attacks Escalate From Zero-Day to Mass Scanning

Here’s your Monday report on immediate and emerging threats. Powered by the CrowdSec Network.

Adobe Commerce and Magento “StyleSmuggler” RCE (CVE-2026-75650): Exploited Before the Patch, Now Sprayed From Home Internet Connections.

CVE-2026-75650 (“StyleSmuggler”) is a CVSS 10.0 unauthenticated remote code execution flaw in Adobe Commerce 2.4.4 to 2.4.9 and Magento Open Source 2.4.6 to 2.4.9. It was exploited three days before Adobe’s fix. CrowdSec has observed 500 unique IP addresses sending matching requests since September 9, 2026. Apply hotfix VULN-39341 now, then check the store for backdoors.

CVE-2026-75650

CVE-2026-75650 at a glance

  • Affected: Adobe Commerce 2.4.4 to 2.4.9, Adobe Commerce B2B 1.3.3 to 1.5.3, and Magento Open Source 2.4.6 to 2.4.9, August 2026 releases included. Older, out-of-support lines received no official patch.
  • Fixed in: Hotfix VULN-39341 (September 7, 2026), bulletin APSB26-146
  • Vulnerability class: Template engine injection leading to PHP code execution (CWE-1336)
  • Severity: CVSS 10.0 Critical
  • Authentication required: None
  • Public exploit: No official PoC, but a public GitHub repository created on September 8 describes itself as a lab reproducing the full unauthenticated chain.
  • CISA KEV: Added September 8, 2026, with a federal deadline of September 11, three days later
  • CrowdSec detection rule live since: September 9, 2026
  • First exploitation attempt observed: September 9, 2026 (in-the-wild exploitation started September 4, per Sansec)
  • Exploitation phase: Rapid Escalation (since September 11, 2026)
  • Observation window used here: September 9 to September 13, 2026 (5 days) for signal counts. Unique-IP counts come from the Live Exploit Tracker and CrowdSec CTI as of September 14, 2026.

Key findings

  • The attack came first, the patch three days later: Sansec spotted StyleSmuggler being used against live stores late on September 4. Adobe shipped hotfix VULN-39341 on September 7, CISA listed it on September 8, and CrowdSec’s detection rule and AppSec virtual patch were live on September 9. Any store reachable between September 4 and the day it was patched has to be checked, not just updated.
  • 2,760 signals in five days, peaking at 1,303 on September 11: Between September 9 and 13, the CrowdSec Network recorded 2,760 signals matching the CVE-2026-75650 pattern, an average of 552 a day. The peak day saw 193 distinct sources. Volume has halved since then but still runs more than ten times above the first day’s level.
  • Two-thirds of the addresses are American home connections: Of the 410 addresses CrowdSec CTI links to this CVE, 265 are in the United States, most of them on Comcast, Charter, Verizon, AT&T, and T-Mobile lines. Yet the US produces only 22% of signals. Many home addresses, each sending a few requests, are part of residential proxy networks or compromised home devices.
  • IP reputation alone will not catch this one: Only 57 of the 410 addresses are on the CrowdSec Intelligence Blocklist as of September 14. Residential exit addresses rotate too fast to be known in advance, so the request-level check does the heavy lifting.

What is Adobe Commerce, and who is exposed to CVE-2026-75650?

Adobe Commerce, and its free sibling Magento Open Source, runs the online shops of a large share of mid-sized retailers and brands: catalogue, cart, checkout, customer accounts and payment integrations. It is usually managed by an e-commerce team or an agency and hosted at a specialist provider.

Why CVE-2026-75650 matters: Code execution on a Magento server means the attacker sits where card data is entered, customer records are stored, and the database password lives. Sansec found a Rust backdoor disguised as system processes that beacons to its operators over traffic shaped like time-sync (NTP) packets, and a second actor dropping a PHP web shell into the product image cache. That is the setup for card skimming and for reselling access to the store.

CrowdSec CTI classifies 98% of the observed intent as infrastructure takeover. Where the sector is known, hosting providers account for 82% of the targeted signals, which fits a platform most merchants run on managed hosting. Germany accounts for 53% of targeted signals and France for 14%. This describes where CrowdSec has visibility, not where Magento is deployed worldwide.

How does CVE-2026-75650 work?

The attack happens in two stages, both without logging in. First, the attacker plants PHP code in data Magento writes to its own logs and reports. Public reports show three ways in: the query string of the PayPal Payflow /paypal/transparent/response/ endpoint, the Store header of a GraphQL request, and styles[...] parameters sent to /graphql. Second, the attacker triggers Magento’s standard “Payment Transaction Failed Reminder” email. While rendering that template, Magento processes the poisoned style data and executes the planted code, whether or not the email is ever delivered.

The root cause: Magento treats style properties as harmless layout data, so they pass its template safeguards unchecked, and its dependency-injection machinery can be steered into running what was planted. That is where the name comes from.

  • Discovered and named by the Sansec Forensics Team, who also published the backdoor indicators and hunting commands.
  • Vendor advisory: Adobe APSB26-146 · Fix: hotfix VULN-39341 from repo.magento.com

StyleSmuggler is the second critical Magento flaw in our alerts within a year, after SessionReaper (CVE-2025-54236) last autumn. The overlap in sources is visible: 23 of the 410 addresses hitting StyleSmuggler also tried SessionReaper, and 35 tried the WordPress flaw WP2Shell (CVE-2026-63030). Whoever is running these scanners is shopping for e-commerce and CMS servers in bulk.

What is the CrowdSec Network observing for CVE-2026-75650?

Between September 9 and September 13, 2026, the CrowdSec Network recorded 2,760 signals from machines reporting requests that match the CVE-2026-75650 exploitation pattern, detected by the CrowdSec scenario released on September 9, 2026. That averages 552 signals per day, peaking at 1,303 on September 11 with 193 distinct sources. The Live Exploit Tracker counts 500 unique IP addresses as of September 14 and moved the CVE into Rapid Escalation on September 11.

By signal volume, sources are spread across the United States (22%), Singapore (13%), Indonesia (8%), the Netherlands (8%), and Cambodia (7%). By address, the picture is different: 65% of the 410 addresses in CrowdSec CTI are American, and 155 of those are classified as residential. The two views disagree because each home address sends only a handful of requests, while 14 hosting and VPN addresses in Singapore sent 349.

The key takeaway is how bursty the traffic is. Indonesia contributed 221 signals on September 11 and almost nothing on any other day. Mexico, Denmark, and Kosovo each appeared for a single day too. That looks like several operators each running one sweep through their own infrastructure, rather than one campaign growing steadily. CrowdSec’s analysis describes an even mix of opportunistic and targeted actors, with volume starting to dip. Rapid Escalation is the phase where a CVE gets folded into commodity toolkits, and the overlap with SessionReaper and WP2Shell suggests that has already happened.

What this data does not show

  • A matching request is an exploitation attempt. CrowdSec cannot confirm any of them succeeded, and a store running hotfix VULN-39341 is not affected by them.
  • 500 unique IP addresses are not 500 threat actors. Residential proxy networks let one operator send traffic through thousands of home connections.
  • These counts come from traffic reaching machines participating in the CrowdSec Network: a sample, not a census.
  • CrowdSec’s first observation on September 9 is not the start of exploitation. Sansec documented compromised stores from September 4, before any public detection rule existed.
  • Five days is a short window. The trend line should not be read as a forecast.

What defenders get wrong about CVE-2026-75650

The first mistake is treating the hotfix as the end of the incident. StyleSmuggler was a zero-day for three days, and the backdoors Sansec found persist through cron jobs and survive a code update. If your store was online and unpatched at any point after September 4, hunt before you relax: look for PHP files under pub/media, unexpected cron entries, and processes named fc-cache or chronyd running from user or temp directories. Then rotate the Magento encryption key, admin passwords, API tokens, and database credentials. Patching closes the door; it does not show you who already walked through.

The second is expecting IP blocklists to absorb this one. They help against the cloud addresses that repeat across campaigns, but only 14% of the addresses hitting CVE-2026-75650 are on the Intelligence Blocklist. When sources are rotating home connections, blocking must happen based on what the request contains, not where it comes from.

Where edge blocking has limits: the CrowdSec virtual patch looks for PHP opening tags in the URL and the Store header, the vectors in the public reports. It does not inspect request bodies. It is a bridge to the hotfix, not a substitute for it.

How do you protect Adobe Commerce against CVE-2026-75650?

Patch. Apply hotfix VULN-39341 from APSB26-146 to every Adobe Commerce, B2B, and Magento Open Source instance, including staging copies that face the internet. Confirm with vendor/bin/magento-patches -n status | grep "39341\|Status", as suggested by Sansec. Stores on out-of-support versions have no official patch; community backports exist, but the real fix is an upgrade.

Virtual patching with CrowdSec AppSec. Until the hotfix is on every instance, the CrowdSec AppSec Component inspects HTTP requests before they reach Magento and blocks those matching crowdsecurity/vpatch-CVE-2026-75650: PHP code in the URL of any request, or in the Store header.

Preemptive blocking. Subscribe to real-time updates on the Live Exploit Tracker page for CVE-2026-75650 to block the addresses behind this activity as they appear. Coverage goes beyond StyleSmuggler: the tracker also follows more than 15 other CVEs and 3 fingerprinting behaviors linked to Adobe Commerce, which together account for 12,000 highly rotating IP addresses reported by the CrowdSec Network over the 14 days to September 14, 2026. When addresses rotate that fast, a list only helps if it updates just as fast. Query the observed sources in CrowdSec CTI.


Written by Matthieu Mazzolini, Data Team Lead, CrowdSec. Published September 14, 2026.

Sharing insights and taking swift action can collectively reduce the impact of these threats. This is your call to action for real-time threat intelligence and collaborative cybersecurity.

If you’re already subscribed, feel free to like and share this post to help your network stay informed about current threats.

WRITTEN BY