If your organisation runs an online store on Adobe Commerce or Magento Open Source, you are almost certainly vulnerable right now — and if you were running it unpatched between September 4 and September 7, 2026, you may already be compromised. That is the stark reality of CVE-2026-75650, a maximum-severity zero-day remote code execution flaw dubbed StyleSmuggler that Adobe’s own security bulletin describes as “critical” and has confirmed is being actively exploited in the wild. Attackers did not wait for a patch. They found it, weaponised it, and backdoored stores for three full days before Adobe shipped a fix. This post breaks down exactly what happened, what was deployed on victims’ servers, and what every Indian IT leader running Magento must do today.

Key Takeaways

  • CVE-2026-75650 (CVSS 10.0) — an unauthenticated RCE zero-day in Magento and Adobe Commerce, confirmed actively exploited before a patch existed.
  • All versions from Adobe Commerce / Magento Open Source 2.4.4 through 2.4.9 and Adobe Commerce B2B 1.3.3–1.5.3 are affected.
  • Exploitation began September 4, 2026; Adobe’s emergency hotfix (APSB26-146 / VULN-39341) arrived September 7, 2026 — a three-day window of unpatched exposure.
  • Two distinct threat actors deployed payloads: a Rust-based Linux backdoor masquerading as system processes, and a PHP web shell hidden in the product image cache.
  • Patching alone is not enough — stores exposed before September 7 must conduct full incident response and rotate all credentials.
  • Indian e-commerce retailers and payment gateway integrators running Magento should treat this as a P1 incident until remediated.

What Is StyleSmuggler? A Technical Breakdown

StyleSmuggler exploits a flaw in the way Magento’s template engine processes style-related properties when generating transactional emails. Specifically, an unauthenticated attacker can inject arbitrary PHP code into a template’s styles properties. When Magento subsequently processes a Payment Transaction Failed Reminder email, it renders the poisoned template — executing the injected payload with the privileges of the web server process.

What makes this particularly dangerous is the complete absence of any authentication requirement. An attacker needs nothing more than network access to the Magento storefront. No admin credentials, no prior foothold, no social engineering. The attack vector is network-accessible, attack complexity is low, and privileges required are none — the three conditions that collectively push a CVSS score to its theoretical maximum of 10.0.

Attribute Detail
CVE ID CVE-2026-75650
CVSS Score 10.0 (Critical)
Attack Vector Network (unauthenticated)
Affected Products Adobe Commerce 2.4.4–2.4.9, Magento Open Source 2.4.6–2.4.9, Adobe Commerce B2B 1.3.3–1.5.3
Patch / Advisory APSB26-146 / Hotfix VULN-39341 (September 7, 2026)
Active Exploitation Confirmed — since September 4, 2026

How the Attack Unfolded: Dual Threat Actors, One Zero-Day

Security researchers at Sansec, the e-commerce-focused threat intelligence firm that first documented the attacks, observed something unusual: two separate threat actors exploiting the same zero-day on the same victim stores simultaneously. This indicates the vulnerability was either independently discovered by multiple groups or shared within closed criminal forums before Adobe had any awareness of it.

Actor 1 deployed the primary payload — a sophisticated, cross-architecture Rust-based Linux backdoor. The implant supports both x86-64 and arm64 architectures and communicates with its command-and-control (C2) infrastructure by disguising traffic as NTP (Network Time Protocol) on UDP port 123. This is a clever evasion technique: most firewalls and SIEM rules do not scrutinise outbound NTP traffic, and defenders rarely block port 123. The malware masquerades as legitimate system processes — [kworker/u:8:0], fc-cache, and chronyd — making it nearly invisible in a ps aux listing. C2 domains observed include typosquat hostnames such as ntp.timesync.to, time.microsft.run, and pool.microsft.studio.

Actor 2 planted a compact 485-byte PHP web shell in a path most administrators would never inspect: pub/media/catalog/product/cache/ss_<10hex>/sync_<10hex>.php. The shell requires a specific X-Cache-Token header to activate, making automated scanners less likely to detect it. This actor also used oast.site subdomains to exfiltrate reconnaissance data — server details, directory writability, environment variables — before establishing persistence.

Three Days of Silent Compromise

The timeline of StyleSmuggler is a masterclass in why zero-day vulnerability management matters so much:

  • September 4, 22:20 UTC: Sansec confirms first exploitation in the wild. At this point, no patch exists.
  • September 5, 07:15 UTC: Sansec Shield (a WAF-layer signature) begins blocking attack attempts. Stores without WAF protection remain fully exposed.
  • September 6: Attackers rebrand their implant to fc-cache, likely in response to initial detection signatures.
  • September 7, 20:20 UTC: Adobe publishes APSB26-146 and releases hotfix VULN-39341 — three days and ~22 hours after exploitation began.
  • September 8: Third-party vendors backport patches to 41 legacy Magento versions that Adobe itself does not officially support.

Every store that was publicly reachable during this window must assume it is compromised until proven otherwise by forensic investigation.

India’s E-Commerce Exposure: Why This Matters Here

India’s e-commerce ecosystem is vast. From D2C brands in Tier-1 cities to regional retailers serving Bharat’s rapidly digitising market, Magento and Adobe Commerce power thousands of Indian storefronts. Many of these stores handle UPI payment flows, store card tokenisation data, and maintain customer PII — exactly the data profile that makes them attractive targets for financially motivated threat actors. India’s e-commerce market, projected to cross $200 billion by 2028, is increasingly on the radar of organised cybercriminal groups.

StyleSmuggler is not a theoretical risk for Indian retailers. Much like the Gitea supply chain RCE and the JFrog Artifactory auth bypass we covered earlier, this attack demonstrates that the software your business runs on is as critical an attack surface as the software you build. The Rust backdoor’s C2 disguised as NTP traffic will pass through most corporate firewalls without any alert. The PHP web shell hidden in the product image cache directory is unlikely to be caught by a simple file-integrity check. If your organisation uses a managed Magento hosting provider, you need to ask them — today — whether VULN-39341 has been applied and whether their infrastructure was scanned for the known indicators of compromise.

What You Should Do Right Now — Sanjay Seth’s Expert Action Plan

As a cybersecurity consultant with three decades of experience in network security and zero-trust architecture, here is the prioritised response plan I recommend for any organisation running Adobe Commerce or Magento Open Source:

  1. Apply Hotfix VULN-39341 immediately. Download VULN-39341-composer-patches.zip from repo.magento.com and apply it via Composer. Enable maintenance mode first, suspend cron jobs, then apply and verify: vendor/bin/magento-patches -n status | grep "39341\|Status".
  2. Assess your exposure window. If your store was publicly accessible between September 4 and September 7, you must conduct a full incident response — not just patch and hope.
  3. Search for backdoor indicators. Hunt for the process names [kworker/u:8:0], fc-cache, and chronyd in unusual paths. Check cron jobs for */5 * * * * or 13,43 * * * * patterns in unexpected locations. Inspect ~/.local/share/.gvfsd/, ~/.cache/fontconfig/, and /tmp/.chrony-*/.
  4. Scan the media directory for web shells. Look for PHP files in pub/media/catalog/product/cache/ matching the pattern sync_<10hex>.php. These do not belong there.
  5. Rotate all credentials. Adobe explicitly recommends rotating admin passwords, API tokens, database credentials, SSH keys, and Commerce encryption keys. Do not skip this step — the backdoor’s purpose is credential harvesting and persistent access.
  6. Block the known C2 IPs at perimeter. At your FortiGate or perimeter firewall, add deny rules for: 88.216.72.181, 182.182.152.48, 76.31.99.207, 209.73.130.148, 77.239.124.107, and 99.84.67.186. Also block DNS resolution for the NTP-spoofing domains listed in the Sansec advisory.
  7. Implement a WAF rule. If you are running FortiWeb or another web application firewall, deploy a custom rule to detect injection attempts targeting Magento’s styles template properties. This will also protect stores on legacy versions for which no official patch exists. FortiGate’s integrated security stack makes it well-suited to this kind of layered web-layer defence.
  8. Notify your customers if compromised. Under India’s Digital Personal Data Protection Act (DPDPA), a breach involving personal data requires notification. Do not delay this step.

For organisations on legacy Magento 2.2, 2.3, or 2.4.0–2.4.3 — versions Adobe does not officially patch — reach out immediately for a migration and interim hardening assessment. Running end-of-life e-commerce software with CVSS 10.0 vulnerabilities in the wild is an unacceptable risk posture.

Frequently Asked Questions

Is my store safe if I applied all previous Adobe Commerce patches?

No. StyleSmuggler was a genuine zero-day — meaning the vulnerability existed in fully patched stores running the latest release (2.4.9 August 2026). Stores that kept up with all prior security updates were still vulnerable until VULN-39341 was applied. This is why the phrase “patch your software” is necessary but not sufficient — zero-days by definition bypass your current patch posture.

How do I know if my store was compromised before the patch was available?

The strongest indicators are the known backdoor process names and cron persistence patterns listed in this post. You should also check your server’s outbound network connections — specifically for unexpected UDP traffic on port 123 to non-legitimate NTP servers. Review your web server access logs for requests to PHP files in the media cache directory that shouldn’t exist. If you have a SIEM or NDR tool, query for connections to the known C2 IP addresses. When in doubt, engage a forensics firm — the cost of a missed compromise in a payment-card environment is far higher than an IR engagement.

We use a managed Magento hosting provider — are we protected?

Ask, do not assume. Contact your hosting provider and request written confirmation that VULN-39341 has been applied and that their infrastructure was scanned against the StyleSmuggler IoCs. Reputable managed Magento hosts like Nexcess and Adobe Commerce Cloud will have applied the patch; smaller providers may still be catching up. If you cannot get a straight answer within 24 hours, consider that a red flag.

What does this mean for PCI DSS compliance?

A store compromised through StyleSmuggler — even briefly — will have compliance implications. PCI DSS v4.0 Requirement 12.10 mandates incident response, and the exposure of cardholder data or payment flows to an unauthenticated backdoor will trigger reporting obligations to your acquiring bank and payment brands. Act now, document everything, and engage your QSA for guidance on breach notification timelines.

Outbound References


Is your Magento store or e-commerce infrastructure protected?

StyleSmuggler proves that even fully patched, production-grade systems can be compromised overnight by a sophisticated zero-day. Whether you need urgent IR triage for a potentially exposed store, a WAF deployment to block web-layer attacks, or a zero-trust network architecture review, contact Sanjay Seth today for a professional security assessment. With 30 years of enterprise cybersecurity experience serving organisations across Delhi NCR and beyond, we can help you respond fast and build defences that hold. Schedule a consultation →