Your Adobe Store Can Be Hacked Without a Password
Most attacks require a username and password. StyleSmuggler doesn’t.
A zero-day vulnerability has been under active exploitation since September 4, 2026. It allows attackers to take complete control of any Magento or Adobe Commerce store. No login. No credentials. No warning.
What Is StyleSmuggler
StyleSmuggler is the name given by the Dutch security firm Sansec to the vulnerability CVE-2026-75650. It is a remote code execution vulnerability without authentication.
Simply put, an attacker sends a specially crafted request to your store. Magento processes it normally. However, inside that request is malicious PHP code. Once executed, the attacker gains full access to the server.
Furthermore, the attack requires no interaction from the user or their customers. It runs silently in the background.
Why Is This Different From Other Vulnerabilities
Most security vulnerabilities target outdated or unpatched stores. StyleSmuggler is different.
The first confirmed victim was using version 2.4.6. All its July and August 2026 security patches were fully applied. Being up-to-date didn’t protect them.
Furthermore, StyleSmuggler affects all current versions. This includes 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8, and 2.4.9. There are no secure versions on this list. StyleSmuggler exposed every Adobe Commerce and Magento store.
How the Attack Works
The exploit runs in two stages. Both stages use Magento’s own systems against it.
First, the attackers manipulate a GraphQL request to inject PHP code into a file. Magento generates this file during normal operations. Specifically, a failed payment transaction reminder email triggers the execution.
Consequently, the server executes the attacker’s code. In confirmed attacks, they install a Rust-based Linux backdoor. This backdoor connects to an external server and waits for instructions. They also install a PHP web shell for persistent, hidden access. This access survives even after the merchant patches the vulnerability.
How Fast It Happens
Speed is what makes this especially dangerous.
One store was completely compromised just 50 minutes after the first confirmed attack was reported. Another was infiltrated within an eight-hour window. Meanwhile, Sansec issued its advisory before even completing its full analysis. Stores were being compromised in real time as it did.
By the time most merchants heard about StyleSmuggler, stores were already being breached via a backdoor.

What Adobe Released and What You Must Apply
Adobe has released two separate patches. Both must be installed; they are not interchangeable.
- APSB26-138 – the standard September security update, released on September 8, 2026. It covers critical, important, and moderate vulnerabilities for all versions ranging from 2.4.4 to 2.4.9.
- APSB26-146 (emergency patch for CVE-2026-75650) – released on September 7, 2026. This is the specific patch for StyleSmuggler. It is not included in APSB26-138 and must be installed separately.
Adobe strongly recommends installing the emergency patch for vulnerability CVE-2026-75650 as soon as possible. Additionally, rotate your encryption keys and credentials as part of your remediation efforts.
These patches are provided as standalone files, not as Composer packages. Install them in the order of release corresponding to your version. Use the “Commerce Version Tool” to confirm that your store is fully protected.
What Every Merchant Should Do Right Now
First, apply the urgent hotfix APSB26-146 for vulnerability CVE-2026-75650. Then, apply the standalone September patch (APSB26-138) that corresponds to your version. You can apply the urgent hotfix either before or after. There is no specific required order between the two.
Once you apply the patches, run the “Commerce Version Tool” from your project root. It will indicate exactly which patches are installed and which CVEs your store is protected against.
If you use Adobe Commerce on Cloud, apply the patches via “Magento Cloud Patches.” Adobe has streamlined this process. Cloud merchants can now stay up to date without having to manually manage patch files.
Final Thought
The StyleSmuggler incident serves as a reminder that security is not a one-time task. Even a fully updated store was compromised. When a “zero-day” vulnerability emerges, the window between discovery and exploitation can be a matter of hours.
The patch is available. The solution is simple. There is no reason to wait.
If you are unsure whether your store has been patched correctly, reach out to us at marketing@tychons.com. The same goes if you need help with the remediation process. We will check your version, confirm your patch status, and make sure your store is protected.
