On 4 September 2026, attackers silently began compromising online stores worldwide — three full days before Adobe even knew a patch was needed. The weapon was StyleSmuggler, a name coined by e-commerce security researchers at Sansec for a freshly discovered unauthenticated remote code execution vulnerability in Adobe Commerce and Magento Open Source. Assigned CVE-2026-75650 with a perfect CVSS score of 10.0, this flaw let any anonymous attacker run arbitrary PHP code on a store’s server, harvest payment data, and plant persistent backdoors — no account, no password, no click from any user required. Three weeks later, thousands of Indian and global merchants remain unpatched, and — critically — many who did patch have not yet checked whether an attacker already got there first.

Key Takeaways

  • CVE-2026-75650 (StyleSmuggler) carries a CVSS 10.0 — the highest possible severity — and enables unauthenticated remote code execution with zero user interaction.
  • Active exploitation started on 4 September 2026, three days before Adobe shipped hotfix VULN-39341 on 7 September.
  • Affected platforms: Adobe Commerce 2.4.4–2.4.9, Adobe Commerce B2B 1.3.3–1.5.3, and Magento Open Source 2.4.4–2.4.9.
  • Observed payloads include a Rust-based Linux backdoor masquerading as chronyd or fc-cache, and a stealth PHP web shell that returns HTTP 404 until a secret header unlocks it.
  • CISA added CVE-2026-75650 to its Known Exploited Vulnerabilities catalog on 8 September 2026; federal remediation deadline was 11 September.
  • Applying the patch is necessary but not sufficient: Adobe explicitly requires encryption-key rotation, and any store that was exposed before 7 September must run full forensic process and file audits.

What Is StyleSmuggler and Why Does It Score 10.0?

Most critical vulnerabilities require at least some form of authentication or a logged-in victim to click something. StyleSmuggler needs neither. The root cause, classified under CWE-1336 (Improper Neutralisation of Special Elements Used in a Template Engine), is buried deep inside Magento’s email-notification pipeline.

Here is the attack chain in plain terms:

  1. An unauthenticated attacker sends a specially crafted HTTP request that coerces Magento’s logging or reporting subsystem into writing attacker-controlled PHP fragments into a file the application can later access — for example, a payment-transaction log or a debug report.
  2. A second request triggers Magento’s dependency-injection (DI) scanner — part of the framework’s routine build-cache process — to load that poisoned file using PHP’s include or require_once.
  3. The injected PHP executes with the full privileges of the web server process, providing a direct shell onto the host. No administrator login was ever involved.

The attack is triggered specifically when the store assembles its routine “Payment Transaction Failed Reminder” transactional email — a process that runs on virtually every Adobe Commerce installation with standard order-management flows enabled. Because no authentication bypass is involved (the endpoint was simply never meant to be authenticated), there are no login logs, no session tokens to revoke, and no WAF rule that trivially blocks all variants. Attackers observed by Sansec had already adapted the template-injection lure to evade early signature-based detections before Adobe’s patch was even published.

Affected Versions at a Glance

Product Vulnerable Versions Fixed By
Adobe Commerce 2.4.4 – 2.4.9 (Aug 2026 builds and earlier) Hotfix VULN-39341
Adobe Commerce B2B 1.3.3 – 1.5.3 Hotfix VULN-39341
Magento Open Source 2.4.4 – 2.4.9 (Aug 2026 builds and earlier) Hotfix VULN-39341

Source: Sansec StyleSmuggler research and Tenable FAQ.

The Payloads: A Rust Backdoor Built for Stealth

Sansec’s incident-response teams observed two distinct payload families deployed during the zero-day window (4–7 September):

1. Rust-Based Linux Backdoor

The more sophisticated payload is a compiled Rust binary designed specifically to evade the detection methods that defenders most commonly use in post-breach forensics:

  • Process masquerade: The backdoor renames itself at runtime to match common Linux system process names — [kworker/u:8:0], fc-cache, and chronyd (the NTP daemon) — so it vanishes into a ps aux listing.
  • NTP-shaped C2 traffic: Rather than opening an obvious reverse shell, the implant sends 48-byte UDP packets on port 123 — indistinguishable from legitimate NTP traffic to most firewalls and network monitoring tools. Observed C2 infrastructure included IP 99.84.67.186.
  • Cron-spool persistence: Instead of running crontab -e (which generates auditable syslog entries), the malware writes directly to the raw cron spool file, achieving reboot persistence without leaving the traces that most SIEM correlation rules look for.

2. PHP Web Shell with Dead-Man’s-Switch Design

A second attacker group deployed a PHP web shell with an innovative evasion technique: it returns a genuine HTTP 404 Not Found to every unauthenticated request. Only a POST request carrying a specific secret in the X-Cache-Token HTTP header unlocks the shell and passes PHP code for execution. Automated scanners and most web-application firewalls, which look for characteristic 200-OK or 500-error responses from shells, would miss this entirely.

Timeline: How the Zero-Day Unfolded

  • 4 September 2026: Sansec observes the first StyleSmuggler attacks against live production stores.
  • 7 September 2026: Adobe releases Hotfix VULN-39341 via repo.magento.com.
  • 8 September 2026: CISA adds CVE-2026-75650 to its KEV catalog; federal agencies given until 11 September to remediate.
  • 9 September 2026: CrowdSec publishes a virtual-patch AppSec rule; public detection signatures begin appearing.
  • 30 September 2026 (today): Thousands of unpatched installations remain reachable; forensic teams continue finding pre-planted backdoors on stores that have since patched.

The India Angle: Why This Hits Closer to Home

India’s e-commerce ecosystem runs heavily on Magento and Adobe Commerce, from mid-market D2C brands in Bengaluru to large B2B distributors in the NCR. A compromised Magento storefront is a direct path to:

  • Payment skimming — injecting malicious JavaScript (Magecart-style) into the checkout flow to harvest card details in transit, which falls under RBI’s card-data protection requirements and PCI-DSS audit scope.
  • Customer PII exfiltration — addresses, phone numbers, and order history, triggering obligations under India’s Digital Personal Data Protection (DPDP) Act 2023.
  • Supply-chain pivot — a compromised Magento admin panel that can push updates to a merchant’s own customers or integrate with third-party logistics and payment partners.

Indian organisations that operate on-premises or private-cloud Magento deployments may lack the automated patch-deployment pipelines that managed SaaS platforms provide. The three-day zero-day window, combined with slow internal patching cycles, means many stores were exposed before the hotfix was even available — making forensic investigation as important as patching.

What You Should Do Right Now

Sanjay Seth’s advice for every organisation running Adobe Commerce or Magento Open Source:

Step 1 — Apply Hotfix VULN-39341 Immediately

Install Adobe’s hotfix from repo.magento.com. This is the only vendor-sanctioned fix; there is currently no full-version upgrade path that addresses StyleSmuggler without the hotfix.

Step 2 — Rotate Your Encryption Keys (Mandatory, Not Optional)

Adobe’s remediation guidance explicitly requires rotating the Magento encryption key stored in app/etc/env.php as a second step. An attacker with RCE access can exfiltrate this key; with it, they can decrypt stored payment tokens and credentials even after the code vulnerability is closed. This step is frequently skipped by teams who only apply the hotfix. Do not skip it.

Step 3 — Run a Forensic Process and File Audit

If your store was running a vulnerable version before 7 September 2026, assume it may have been compromised. Specifically check:

  • ps aux | grep -E 'chronyd|fc-cache|kworker' — look for processes running from unexpected paths (e.g., /tmp, /var/www, user home directories)
  • Raw cron spool files under /var/spool/cron/ for unexpected entries
  • Outbound UDP traffic on port 123 to non-NTP IP addresses
  • PHP files in pub/media, var/log, and cache directories that contain executable code
  • Any file responding to requests with a X-Cache-Token header parameter

Step 4 — Harden Your Network Perimeter

A zero-trust architecture with FortiGate segmentation would have limited the blast radius here: even if the web server was compromised, strict east-west traffic rules would have prevented lateral movement to databases, internal APIs, and payment systems. If your e-commerce environment is not segmented from your internal network, that changes today. Consider a perimeter security review alongside your patching effort.

Step 5 — Enable Application-Layer Inspection

Deploy a web application firewall rule blocking the template-injection pattern (CrowdSec has published a free AppSec virtual patch). For Adobe Commerce Cloud customers, Adobe has stated that cloud infrastructure is already patched — but do verify, and still check for indicators of compromise if your store was live during the zero-day window.

Frequently Asked Questions

Is Adobe Commerce Cloud affected?

Adobe has confirmed that Adobe Commerce Cloud infrastructure was patched before the public disclosure on 7 September 2026. However, customers operating self-hosted or hybrid deployments on versions 2.4.4 through 2.4.9 are fully affected and must apply VULN-39341 manually. If you are unsure of your deployment model, check with your hosting provider and validate your Magento version with php bin/magento --version.

Can I detect exploitation attempts in my web server logs?

Standard access-log scanning may not catch StyleSmuggler — the initial injection request looks like a legitimate store interaction, and the DI-scanner trigger can look like a routine cache-rebuild operation. Sansec recommends using their free StyleSmuggler detection script which checks for known payload artefacts and suspicious file modifications. Look specifically for unexpected modifications to files in the generated/ and var/ directories in the September 4–7 window.

Does this affect Magento 1.x stores?

No. The vulnerable template-processing code path is specific to the Magento 2.x architecture. However, Magento 1.x reached end-of-life in June 2020 and has had no security patches since. Operators still running Magento 1.x face a wide variety of other unpatched critical vulnerabilities and should treat migration to Magento 2.x (or an alternative platform) as an urgent business continuity priority.

We patched on September 8 — are we safe?

Patching closed the door, but the lock may already have been picked. If your store ran a vulnerable version between 4 September and the time you applied VULN-39341, run Steps 2 and 3 above regardless of how quickly you patched. The Rust backdoor survives code updates and persists through reboots via the cron-spool mechanism — it will remain active until explicitly identified and removed.

Conclusion: Patch, Rotate, and Investigate

StyleSmuggler is a reminder that maximum-severity vulnerabilities are not theoretical. When attackers had a three-day head start with a CVSS 10.0 zero-day against one of the world’s most widely deployed e-commerce platforms, the organisations that came out cleanest were those with defence-in-depth: network segmentation that limited what a compromised web server could reach, WAF rules that bought time, and incident-response playbooks that did not stop at “we applied the patch.”

For Indian businesses, the combination of DPDP Act compliance obligations, RBI card-data guidelines, and a customer base that increasingly shops online makes Magento security a board-level issue, not just an IT checkbox. The question is not whether to take this seriously — it is whether your security posture is being reviewed by someone who can see across your entire perimeter before the next zero-day lands.

If you are an IT leader, CISO, or business owner running Adobe Commerce or Magento — or you are simply not certain what your e-commerce security posture looks like — reach out for a security assessment. The StyleSmuggler forensic checklist is something we run as part of every engagement for commerce-connected environments right now. Let’s make sure your store is clean.