NG Solution Team
Cybersecurity

StyleSmuggler: Apply Adobe Commerce and Magento Hotfix Now

A critical vulnerability tracked as CVE-2026-75650 and known as “StyleSmuggler” was being actively exploited before a hotfix became available. Adobe has released a fix; site operators running supported versions of Adobe Commerce or Magento should apply the hotfix immediately.

StyleSmuggler is an unauthenticated remote code execution (RCE) flaw that can give attackers deep access to a store and its customers’ data, including credit card information. CrowdSec warned of the practical consequences, saying: “Code execution on a Magento server means the attacker sits where card data is entered, customer records are stored, and the database password lives. Sansec found a Rust backdoor disguised as system processes that beacons to its operators over traffic shaped like time-sync (NTP) packets, and a second actor dropping a PHP web shell into the product image cache. That is the setup for card skimming and for reselling access to the store. CrowdSec CTI classifies 98% of the observed intent as infrastructure takeover.”

StyleSmuggler risks and affected versions

Every currently supported release of Magento and Adobe Commerce is affected. The listed affected versions are:
– Magento Open Source: 2.4.6 to 2.4.9.
– Adobe Commerce: 2.4.4 to 2.4.9.
– Adobe Commerce B2B: 1.3.3 to 1.5.3.

Versions older than those ranges are out of support and therefore vulnerable. Adobe recommends updating to a supported release before applying the hotfix where possible.

Even if your infrastructure is managed by a third party, this hotfix must be applied by the site owner: managed services typically cover the infrastructure layer (for example, OS or kernel patches) but do not substitute for application-layer updates. To start remediation, consult Adobe’s security bulletin, which includes the hotfix and installation instructions.

Apply the hotfix to Magento or Adobe Commerce as soon as possible to mitigate active exploitation and reduce the risk of data theft or infrastructure takeover.

Related posts

Has Novo Nordisk Fallen Victim to a Major Cybersecurity Breach?

Emily Brown

Is Your Chrome Browser at Risk from a Zero-Day Exploit?

David Jones

Is the US embassy in Bahrain warning Americans to shelter as sirens sound nationwide?

Emily Brown

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy