StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
Imported from official source
A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication. Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different attack campaigns. Adobe released Hotfix VULN-39341 on September 7, 2026, and Tenable detection plugins will be published as they become available. Tenable's Research Special Operations Team (RSO) has compiled this blog to answer Frequently Asked Questions (FAQ) regarding CVE-2026-75650, a zero-day remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that has been actively exploited in the wild. When was CVE-2026-75650 first disclosed? On September 5, 2026, the Sansec Forensics Team published research detailing an actively exploited zero-day vulnerability in Mag...
This version
- Version
- 2 of 2
- Recorded
- September 24, 2026 19:00
- Change
- Imported change
- Content hash
183268fd390c752d9ccfae3cecdb6715- All versions
- Revision history