WHAT HAPPENED
aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants. s template system. An attacker injects PHP through the template path used to generate the s own template-processing and dependency-injection code into an unauthenticated remote-code-execution chain. 0 unauthenticated remote code execution flaw in Adobe Commerce and Magento Open Source that Sansec codenamed StyleSmuggler and observed being exploited as a zero-day from September 4, 2026. impact:Attackers get code execution as the web server with no credentials, and observed payloads include a Rust based Linux backdoor that beacons to an external server plus a PHP dropper that writes an arbitrary-PHP web shell on the checkout host.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY