Key details

  1. Adobe published APSB26-146 on September 7, 2026.
  2. CVE-2026-75650 is rated Critical with CVSS 10.0.
  3. Authentication is not required to exploit the flaw.
  4. Adobe confirms exploitation in the wild.
  5. Affected products include Adobe Commerce, Adobe Commerce B2B and Magento Open Source across current supported 2.4.x-era branches listed in the bulletin.
  6. The remediation is hotfix VULN-39341.
  7. Adobe's regular September security bulletin says the hotfix must be applied in addition to normal September updates.
  8. Sansec says exploitation began September 4, before the Adobe hotfix was available.

What builders should take away

  1. Verify the CVE-2026-75650 hotfix specifically; do not infer protection from being on the latest normal Magento/Commerce patch level.
  2. Treat stores exposed before patching as potential incident-response cases, not merely patch-management tasks.
  3. Rotate secrets at their actual source systems if compromise is suspected; changing only Magento's local encryption key does not invalidate credentials an attacker already copied.
  4. Review failed-payment-email anomalies and other published indicators as hunting signals, but do not rely on one indicator to prove a store is clean.
  5. Keep emergency vendor hotfixes in a separate operational checklist from scheduled Commerce release upgrades so out-of-band fixes are not missed.

What changed

Adobe published out-of-band bulletin APSB26-146 on September 7 for CVE-2026-75650, a critical unauthenticated arbitrary-code-execution flaw in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Adobe assigns CVSS 10.0, priority 1 and confirms exploitation in the wild. Sansec, which named the campaign StyleSmuggler, says attacks began September 4, before the hotfix was available, and reproduced the chain on clean, current Magento installations. Adobe's remediation is a separate hotfix, VULN-39341, rather than simply the scheduled September Commerce release; Adobe's September bulletin explicitly tells customers to apply the CVE-2026-75650 hotfix in addition to normal security updates.

Why it matters

A store can be fully current on normal Magento patching and still have been exposed during the zero-day window. Because attackers had days of access before Adobe shipped the hotfix, remediation is not only about preventing the next request: operators need to check for compromise and rotate secrets that could already have been read. For commerce systems, that can include admin credentials, API/integration tokens, payment-gateway secrets, database credentials and deployment keys.

The flaw is unauthenticated and maximum-severity

Adobe classifies CVE-2026-75650 as improper neutralization in a template engine leading to arbitrary code execution, with no authentication required and a CVSS base score of 10.0.

Exploitation preceded the vendor patch

Sansec says it first confirmed exploitation on September 4 and reproduced the chain on clean supported versions. Adobe released APSB26-146 and the emergency hotfix on September 7, leaving a period where fully patched stores could still be attacked.

The fix is separate from the normal September update

Adobe's regular September Commerce bulletin explicitly instructs customers to apply the CVE-2026-75650 hotfix in addition to the scheduled security update. Operators should verify the hotfix itself is present rather than assuming a routine version update covered the issue.

Patching cannot undo credentials already exposed

Independent responders say compromised stores may have leaked secrets before the fix was installed. Adobe/Sansec guidance emphasizes key and credential rotation plus incident investigation when exposure or compromise is suspected.

What to watch next

  • Whether Adobe folds VULN-39341 into a future full Commerce/Magento release and how it marks the superseding versions.
  • New exploitation techniques or indicators from Sansec and other incident responders.
  • Evidence on compromise scale and affected merchant populations.
  • Any additional Adobe guidance on credential rotation or forensic investigation.

Still unclear

  • Public exploitation counts and affected-store totals are largely based on security-vendor telemetry and may not represent the whole Magento ecosystem.
  • A patched store may still require investigation if it was reachable during the pre-patch exploitation window.
  • The exact attack activity and compromise depth vary by victim; presence of a vulnerable version does not prove successful exploitation.

Sources

Direct reading behind this dossier.

3 sources

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment