# StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

DevFeed: [StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day](<https://devfeed.tech/articles/stylesmuggler-cve-2026-75650-frequently-asked-questions-about-adobe-commerce-and-magento-zero-day-8271.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/stylesmuggler-cve-2026-75650-frequently-asked-questions-about-adobe-commerce-and-magento-zero>)

Author: Satnam Narang

Published: 2026-09-08T14:00:43Z

Content type: news

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [PHP](<https://devfeed.tech/topics/php.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [payload](<https://devfeed.tech/tags/payload.md>), [php](<https://devfeed.tech/tags/php.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

The article explains StyleSmuggler (CVE-2026-75650), an actively exploited, unauthenticated remote-code-execution vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. It describes injection of PHP code through style properties and execution during rendering of a transactional email template.

## Source excerpt

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication. Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different attack campaigns. Adobe released Hotfix VULN-39341 on September 7, 2026, and Tenable detection plugins will be published as they become available. Background Tenable's Research Special Operations Team (RSO) has compiled this blog to answer Frequently Asked Questions (FAQ) regarding CVE-2026-75650, a zero-day remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that has been actively exploited in the wild. FAQ When was CVE-2026-75650 first disclosed? On September 5, 2026, the Sansec Forensics Team published research detailing an actively exploited zero-day vulnerability in Magento and Adobe Commerce that it named StyleSmuggler. What is CVE-2026-75650? CVE-2026-75650 is a remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Successful exploitation grants an unauthenticated attacker the ability to execute arbitrary code on a vulnerable server. CVE-2026-75650 carries a CVSSv3 score of 10.0, the highest possible rating. Additionally, its scope is changed, meaning exploitation can impact resources beyond the vulnerable component itself. CVEDescriptionCVSSv3CVE-2026-75650Adobe Commerce and Magento Open Source Remote Code Execution10.0 The following products and versions are affected: ProductAffected versionsAdobe Commerce2.4.4 through 2.4.9Adobe Commerce B2B1.3.3 through 1.5.3Magento Open Source2