Patching StyleSmuggler Will Not Evict an Attacker From Your Magento Store
A Magento store that was fully patched before StyleSmuggler’s disclosure could still have been compromised. Adobe has since released a hotfix. Installing it closes the vulnerability, but does not establish that an attacker has been removed.
Dutch e-commerce security company Sansec disclosed StyleSmuggler while it was an unpatched Magento Open Source and Adobe Commerce flaw. Its original investigation dated exploitation to 4 September 2026, before a vendor fix existed.
Update, 29 September 2026: Adobe identifies StyleSmuggler as CVE-2026-75650, a critical CVSS 10.0 template-engine flaw permitting unauthenticated arbitrary code execution. Adobe confirms exploitation in the wild. Its 7 September bulletin APSB26-146 supersedes this article’s original no-CVE and no-patch status.
The first victim looked fully patched
Sansec says the first confirmed victim ran Magento 2.4.6-p15 with the July and August 2026 security updates installed. Magento’s own security:patch-status check reported no missing patches.
Sansec reproduced the unauthenticated chain on clean Magento Open Source 2.4.7, 2.4.8 and 2.4.9 installations. At that point, patch reporting could not flag a vendor update that did not yet exist. That historical limitation must not be mistaken for the current position: Adobe’s hotfix is now available.
StyleSmuggler turns a presentation feature into a code path
The attack abuses styles properties in Magento’s template system. Sansec describes a two-stage chain. The attacker first poisons a file with PHP code, for example through a generated failure report. Magento is then induced to parse the poisoned content while rendering a failed-payment email.
Nobody needs to open that message. Execution occurs while Magento renders it, and the attack may still work if delivery fails. A sudden burst of “Payment Transaction Failed Reminder” messages is therefore a useful investigation lead, but the absence of those emails is not evidence that a store is safe.
The chain is important because it crosses a boundary that operators normally treat as safe. Styling data belongs in presentation. StyleSmuggler uses that data to influence a file that the application later handles as executable PHP.
The implant is built to survive
Successful attacks launch a small Rust backdoor as a background process. It connects to command infrastructure and waits for instructions. Sansec had not observed the operators weaponising that command channel at publication, but the foothold already provides persistence and future remote access.
The original malware disguised itself as [kworker/u:8:0], created files under ~/.local/share/.gvfsd/ and installed a five-minute cron job. These are historical indicators, not an exhaustive current detection rule. Use Sansec’s maintained investigation for subsequent variants and indicators, and investigate behaviour beyond a single process name.
What Magento and Adobe Commerce operators should do now
- Apply the correct VULN-39341 patch. Follow Adobe’s current version-specific instructions, updated 21 September. The compatibility table now includes older baselines as well as July and August releases; do not use an outdated August-only checklist.
- Verify installation. Adobe provides a Quality Patches Tool check for Commerce on Cloud. Confirm the applicable hotfix reports as applied, rather than assuming the main release number proves protection.
- Follow the full credential-rotation sequence. Adobe requires encryption-key rotation and rotation of potentially exposed credentials at their source. Changing only Commerce’s encryption key does not invalidate secrets already obtained. Follow its maintenance-mode, cron, rotation and restoration instructions for your deployment.
- Investigate the exposed period. Preserve evidence and review processes, persistence, unexpected PHP files, application reports, failed-payment activity and outbound connections against Sansec’s maintained indicators. Absence of one artefact does not clear the host.
- Recover trust, not just patch status. If compromise is confirmed or integrity cannot be established, isolate and rebuild from a trusted baseline before restoring reviewed configuration.
- Keep temporary controls in proportion. GraphQL restrictions can affect storefronts and integrations. They are supplementary exposure reduction, not a replacement for the hotfix and incident response.
Adobe’s bulletin lists affected Adobe Commerce 2.4.4 through 2.4.9 branches, Magento Open Source 2.4.6 through 2.4.9 branches and Commerce B2B releases. The precise affected baselines and patch files differ. Check both the bulletin and current installation table against the actual deployment; neither a generic “latest Magento” label nor a guessed patch file is a reliable acceptance check.
A green patch dashboard does not settle the incident
StyleSmuggler exposes a blind spot in vulnerability management. Organisations often use patch compliance as a proxy for security. That works only after a vendor has identified the weakness, produced a fix and mapped it to affected releases.
Here, the first victim had done the expected work. The store was current, and the built-in status check was clean. The attacker was operating in the gap between exploitation and vendor remediation.
The zero-day gap closed when Adobe released the hotfix on 7 September. The remaining operational question is whether the store was compromised before it was installed. Combine verified patch state with process, network, persistence and application evidence, and invalidate credentials the attacker may have reached.
Sources and further reading
- Sansec: StyleSmuggler, Magento and Adobe Commerce zero-day RCE under active attack, published 5 September 2026. No publication time was provided. The incident timeline records first confirmed exploitation at 22:20 on 4 September 2026 and blocking rules at 07:15 on 5 September.
- Adobe APSB26-146, published 7 September 2026, confirming CVE-2026-75650 and exploitation.
- Adobe’s VULN-39341 patch and credential-rotation instructions, updated 21 September 2026, checked 29 September.


