Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

CVE-2026-75650, which Sansec has named StyleSmuggler, lets an unauthenticated attacker run code on a vulnerable Magento or Adobe Commerce server. The trigger is an ordinary automated message: Magento’s Payment Transaction Failed Reminder email. When the store renders that template, attacker-supplied PHP is processed on the server, and the reporting does not require the recipient to open anything.

Adobe rates the flaw critical. Its fix is a release-specific hotfix, VULN-39341, and Adobe’s guidance adds encryption-key and credential rotation for any store that may have been exposed. Adobe’s bulletin is the authority for severity and affected versions; the exploit chain described below comes from security-firm reporting. The details here reflect material available as of early October 2026, so check Adobe’s bulletin and support notice against your exact release before acting.

What the flaw is and how serious it is

Adobe published security bulletin APSB26-146 on September 7, 2026 and marked it priority 1. The bulletin classifies the issue as CWE-1336, improper neutralization of special elements in a template engine. Its impact is arbitrary code execution, with no authentication required. The CVSS 3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, which gives a base score of 10.0.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Adobe’s own description of the update is short: “This update resolves a critical vulnerability that could result in arbitrary code execution.” The bulletin does not publish the exploit sequence, so the mechanics in the next section come from Sansec and Tenable.

How the payment-failure email becomes the trigger

Sansec Forensics Team published its threat write-up on September 5, 2026 and updated it on September 14, 2026. Tenable’s FAQ, dated September 8, 2026, independently describes the same render path in broad outline. The chain has three stages. This is a description of the risk, not a reproduction guide.

Stage 1: Attacker-controlled PHP reaches template content

Sansec describes a remote, unauthenticated request that abuses style-related properties in Magento’s template-processing system. The result is attacker-controlled PHP placed into content that Magento writes or handles during normal operation. Sansec calls this poisoning the template system and summarises it as: “StyleSmuggler injects malicious code into Magento’s template system.”

Stage 2: A routine email render executes it

Magento later processes the poisoned material while it renders the Payment Transaction Failed Reminder transactional email. Both Sansec and Tenable identify that template as the render path. Execution happens on the server at render time, so the attacker does not depend on a customer opening a message.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Stage 3: Code runs on the server

Successful execution gives the attacker code execution on the affected server. That server-side foothold is why the vendor and security-firm guidance goes beyond patching, as covered in the incident section below.

The table separates what Adobe confirms from what the security firms report.

Claim Who reports it Status
Critical; CVSS 3.1 base score 10.0; no authentication required Adobe, APSB26-146 (September 7, 2026) Vendor-confirmed
Adobe was aware of exploitation in the wild Adobe, APSB26-146 Vendor-confirmed; no exploitation count published
Style-property abuse places PHP into template-system content Sansec Forensics Team (September 5, updated September 14, 2026) Researcher-reported; not in Adobe’s bulletin
Payment Transaction Failed Reminder email is the render path Sansec; Tenable (September 8, 2026) Researcher-reported; two independent descriptions
Recipient does not need to open the email Sansec; Tenable Researcher-reported
Attacks began September 4, 2026 Sansec Researcher-reported timeline, not an Adobe figure

The lesson for operators is that a routine transactional-email workflow can reach a vulnerable server-side template path. Do not assume that only checkout or admin pages are in scope.

Key dates

  • September 4, 2026: attacks begin, according to Sansec.
  • September 5, 2026: Sansec publishes its threat write-up.
  • September 7, 2026: Adobe publishes APSB26-146. Sansec reports that Adobe released the hotfix the same day.
  • September 8, 2026: Tenable publishes its FAQ.
  • September 14, 2026: Sansec updates its write-up.
  • September 21, 2026: Adobe’s support notice maps VULN-39341 packages to release families.

Which releases are affected

Match your installation to Adobe’s bulletin, which lists the following release families.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Product Lines listed as affected in APSB26-146 Notes
Adobe Commerce 2.4.4 through 2.4.9-2026-aug, and earlier releases within those branches The 2.4.4 to 2.4.9 branches are all listed.
Adobe Commerce B2B Lines 1.3.3, 1.3.4, 1.4.2, 1.5.2, and 1.5.3, and earlier, as enumerated in the bulletin Confirm your exact B2B version against the bulletin’s list.
Magento Open Source 2.4.6, 2.4.7, 2.4.8, and 2.4.9 lines, including 2.4.9-2026-aug, and earlier releases in those branches The bulletin starts Open Source at 2.4.6. For an older Open Source line, check the bulletin directly rather than assuming it is out of scope.

Sansec reports that Adobe tested the hotfix against 2026-aug releases across Commerce and Open Source 2.4.4 to 2.4.9 and B2B 1.3.3 to 1.5.3. Sansec also said that, when it reported, the hotfix had not been verified on older releases within those branches. If you run an older build inside a listed branch, treat coverage as unconfirmed until Adobe’s mapping names your build.

Applying the VULN-39341 hotfix

Adobe’s September 21, 2026 support notice provides VULN-39341 packages for release families, including legacy patch-level branches. Choose the package from that mapping for your exact build. Do not apply a package by filename from a secondary article, including this one.

  1. Record the exact installed product and build. Identify whether you run Adobe Commerce, Adobe Commerce B2B, or Magento Open Source, and note the full release label, including any 2026-aug suffix. A branch name such as 2.4.7 is not enough on its own.
  2. Find your row in Adobe’s VULN-39341 mapping. Open the September 21, 2026 support notice and locate the package for your release family. If your installation sits on a legacy patch-level branch, use the entry for that branch rather than the nearest current release.
  3. Apply the matching package. Follow the installation steps in Adobe’s notice for that package.
  4. Verify the patch is in place. On Adobe Commerce on Cloud, run vendor/bin/magento-patches -n status from the project and search the output for the VULN-39341 entry. Confirm the entry shows the patch as applied. For other deployments, use the verification method in Adobe’s notice. A version number alone does not prove the patch is installed.
  5. Keep the evidence. Save the status output, the package you applied, and the date. You will need that record for the incident steps below.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If the store may have been exposed

Once applied, the hotfix prevents exploitation through this vulnerability. It does not show that an earlier compromise was removed, so the response depends on whether the store may have been exposed while unpatched.

Which steps apply to which situation

Situation Hotfix Encryption key and credential rotation Incident investigation
Unexposed installation Required Not triggered by an exposure window Not indicated by this flaw alone
Possibly exposed while unpatched, or indicators of compromise Required Required: the encryption key and every credential listed below Required, led by a qualified security team

Credentials to rotate

Adobe’s support notice says to rotate the encryption key and all credentials that could have been encrypted or exposed with it. The notice names these categories:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Administrator passwords
  • REST, SOAP, and GraphQL integration tokens
  • OAuth client secrets
  • Payment-gateway API credentials
  • Database and Fastly credentials
  • SSH and deploy keys
  • Privileged service-account credentials
  • Shipping, tax, and other extension API keys

Why rotating the key is not enough

Adobe warns that rotating the encryption key alone does not invalidate credentials an attacker may already have read. The two actions do different jobs.

Action What it changes What it does not do
Rotate the encryption key Replaces the key that protects data encrypted with it Does not invalidate credentials an attacker may already have read
Rotate each credential at its issuing service Issues a new secret and retires the exposed one at its source Does not change the encryption key

Adobe treats both as necessary. Because rotating the key affects the data it protects, plan the two steps as one change window with the people who run payment, shipping, and deployment systems, and follow Adobe’s notice for the procedure.

Investigate as a separate task

  • Scan for implants and secondary backdoors. Sansec recommends this alongside patching and credential rotation.
  • Review activity from September 4, 2026, the date Sansec reports attacks began, through the date you applied the hotfix. Ask the security team to set the window if your exposure began earlier or later.
  • Assign the work to a qualified security team. Tenable notes that patching alone does not remediate an existing compromise.

What the evidence does not establish

  • Scale. No official source publishes the number of affected installations, a prevalence rate, or a victim total, so none is offered here.
  • Current public status. Tenable’s September 8, 2026 FAQ described attribution and public proof-of-concept availability as of that date. Those points may have changed, so check current status before drawing conclusions.

Optional outside help

Sansec’s guidance names its own eComscan and Shield services for scanning and protection. These are commercial options, not part of Adobe’s fix, and the hotfix, credential rotation, and investigation described above do not depend on them.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.