CTIPilot

StyleSmuggler

trend · trend:stylesmuggler-magento-adobe-commerce-2026-09

Sansec's name for an unauthenticated RCE chain in Magento/Adobe Commerce (CVE-2026-75650, CVSS 10.0) that poisons a Magento-rendered log or report file with template code and detonates it via the platform's own failed-payment notification email; exploited in the wild from 2026-09-04, patched by Adobe on 2026-09-07 (Sansec, 2026-09-05).

Aliases: CVE-2026-75650 Magento/Adobe Commerce zero-day

Coverage timeline
1
first 2026-09-08 → last 2026-09-08
Peak priority
critical
1 critical
Sources cited
4
4 hosts
Sections touched
1
deep-dive
Co-occurring entities
4
see Co-occurring entities below
ATT&CK techniques
8
pinned v19.2 · see below

ATT&CK techniques

8 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce · ATT&CK page ↗

Execution TA0002

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce · ATT&CK page ↗

Persistence TA0003

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce · ATT&CK page ↗

Privilege Escalation TA0004

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce · ATT&CK page ↗

Stealth TA0005

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce · ATT&CK page ↗

T1622Debugger Evasion×1

Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads.

Evidence: 2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce · ATT&CK page ↗

Discovery TA0007

T1082System Information Discovery×1

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Evidence: 2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce · ATT&CK page ↗

T1622Debugger Evasion×1

Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads.

Evidence: 2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce · ATT&CK page ↗

Command and Control TA0011

T1001.003Data Obfuscation: Protocol or Service Impersonation×1

Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts. By impersonating legitimate protocols or web services, adversaries can make their command and control traffic blend in with legitimate network traffic.

Evidence: 2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce · ATT&CK page ↗

T1071.004Application Layer Protocol: DNS×1

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-08/stylesmuggler-cve-2026-75650-magento-adobe-commerce-rce · ATT&CK page ↗

Story timeline

  1. 2026-09-08CVE-2026-75650 ("StyleSmuggler"), Magento/Adobe Commerce: unauthenticated CVSS 10.0 RCE via template-engine injection, exploited three days before Adobe's hotfix existed
    deep-diveAdobe rates its own emergency hotfix priority 1 for a flaw stores were already being compromised through since before Sansec published

Where this entity is cited

  • deep-dive1

Source distribution

  • helpx.adobe.com1 (25%)
  • sansec.io1 (25%)
  • security-hub.ncsc.admin.ch1 (25%)
  • thehackernews.com1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about StyleSmuggler (1)

2026-09-08 · view entry permalink →

CRITICALCVE-2026-75650exploitedNATOA1

CVE-2026-75650 ("StyleSmuggler"), Magento/Adobe Commerce: unauthenticated CVSS 10.0 RCE via template-engine injection, exploited three days before Adobe's hotfix existed

Sansec found StyleSmuggler on 2026-09-04 at 22:40 UTC and published the following day specifically because stores were already being compromised, reproducing the full unauthenticated chain on clean Magento Open Source 2.4.7, 2.4.8 and 2.4.9 within hours (Sansec, 2026-09-05). The bug abuses Magento's own template engine through the styles property, reached via a POST /graphql request carrying the malicious styles parameter, to smuggle PHP past existing input safeguards, and runs in two stages: first the attacker poisons a location Magento itself writes to and later re-renders through its template filter; Sansec's own published check searches a failure report under var/report/, but Magento hosting firm Disrex Group, which handled two live compromises, found both of its infections instead poisoned var/log/system.log, a location Sansec's check misses entirely (The Hacker News, 2026-09-06), with attacker-controlled PHP; second, the attacker triggers Magento's built-in "Payment Transaction Failed Reminder" customer-notification email, and the poisoned content executes the moment Magento renders that template (Sansec, 2026-09-05). Nobody needs to open the email, and the attack succeeds even when delivery fails (Sansec, 2026-09-05). Adobe assigned CVE-2026-75650 (CVSS 10.0, CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine) and shipped an emergency hotfix, APSB26-146, on 2026-09-07 at 20:20 UTC with its highest priority rating, three days after the first confirmed exploitation (Adobe PSIRT, 2026-09-07; Sansec, 2026-09-05). The fix ships as a composer patch (VULN-39341) rather than a full point release, tested against the 2026-aug release branch of Adobe Commerce, Adobe Commerce B2B and Magento Open Source 2.4.4 through 2.4.9; older versions in those branches are affected too, but Sansec reports the patch is unverified there (Sansec, 2026-09-05).

Disrex's own two compromises, reported independently of Sansec, sharpen the timeline and the triage picture. Both stores were breached inside the roughly eight-hour window between Sansec's first observed exploitation and the moment any defense existed, and Disrex states patch level was irrelevant during that window; one victim ran Magento Open Source 2.4.8 as a Sansec Shield customer with the module installed, enabled and licensed, and was still hit hours before Shield's first blocking rule went live (The Hacker News, 2026-09-06). Disrex reports a concrete false-negative worth defenders' attention: its own eComscan run on one compromised store returned clean eleven hours after the implant first executed, because the scheduled scan was scoped to the store's document root while the implant had installed itself one directory above it, under the site account's home directory, a scan-scope gap, not a detection-engine failure. Disrex also names a reliable success indicator the exploit itself leaves behind: a TypeError from array_merge() with an integer argument, logged immediately after the poisoned include executes; a stealthier variant instead returns an empty array and leaves nothing to find, so its absence does not clear a host. One of Disrex's two compromises first surfaced through exactly the "Payment Transaction Failed Reminder" tell this entry describes above: a merchant forwarded a failed-transaction email whose template variables had never resolved (raw {{var ...}} tags, a customer address on an invalid domain, a zero-value total) and that forward alone started the investigation that found the implant within the hour (The Hacker News, 2026-09-06).

Patch level offered no protection during the exposure window: the first confirmed victim ran Magento 2.4.6-p15 with the July and August 2026 security patches applied (the latest patch level Adobe offers for that release line) and a clean security:patch-status (Sansec, 2026-09-05; The Hacker News, 2026-09-06), and Sansec's own Shield product blocked a probe against an already-current 2.4.7-p10 store on 2026-09-07, confirming that current patch level was no defense during the exposure window (Sansec, 2026-09-05). Moving session storage to Redis or a database is not a mitigation either: one merchant's session-storage defense stopped one attempt, and the same operator succeeded eight seconds later by routing the poisoned payload through a file uploaded via Magento's custom options instead (Sansec, 2026-09-05). On success, the implant is a small Rust binary (Disrex describes the sample from its own compromises as stripped and statically linked) that installs itself under a hidden directory outside the web root and re-persists via a cron entry written directly into the cron spool file rather than through the crontab command, so the change leaves no corresponding audit line and an empty crontab -l is not evidence of a clean host (Sansec, 2026-09-05; The Hacker News, 2026-09-06). The implant renames its own process to masquerade as a kernel worker thread, the fontconfig cache builder, or the genuine NTP daemon, and one observed build re-dropped and renamed itself mid-run from one masquerade to another while keeping the same underlying agent identity, a process-naming change with no corresponding new infection (Sansec, 2026-09-05). It reads /proc/self/status for TracerPid before beaconing: if a debugger or tracer is attached, the implant still installs itself but never calls out, which matters for anyone attempting to reproduce or analyze it live (Sansec, 2026-09-05).

Command-and-control is disguised as time synchronization: every 60 seconds the implant sends short UDP datagrams to port 123 shaped to resemble NTP server replies, carrying a chunked telemetry record (host, user, operating system, resource usage, and implant version) rather than legitimate time data, traffic that passes most egress filtering unremarked because it looks like a routine NTP exchange (Sansec, 2026-09-05). Two details separate it from a genuine NTP client for a defender who does look: a real client issues one query per interval, where one observed build burst nine datagrams roughly ten milliseconds apart every sixty seconds; and every datagram is marked NTP server-mode, which a client has no legitimate reason to send at all (Sansec, 2026-09-05). Sansec has so far found no evidence the backdoor has been used beyond installation and beaconing (Sansec, 2026-09-05).

Sansec separately documents a second, apparently unrelated actor exploiting the same flaw: a reconnaissance probe sent as an ordinary-looking GraphQL request carries PHP code inside a request header rather than the request body, reads the host's kernel/OS string, PHP user, working directory, and whether the media directory is writable, then exfiltrates that single-line answer one fragment at a time as a sequence of externally-resolved hostname labels to a public callback service; a technique that needs no response body at all, since the operator reconstructs the answer from the callback log (Sansec, 2026-09-05). Only when that probe reports the media directory writable does the same actor follow up with a web shell planted inside the product-image cache directory, reachable solely with a custom request header (Sansec, 2026-09-05).

Every version of Adobe Commerce, Adobe Commerce B2B and Magento Open Source in the 2.4.4–2.4.9 line is affected with no authentication or user interaction required (Adobe PSIRT, 2026-09-07); Switzerland's NCSC has issued its own advisory confirming the exploitation and backdoor-persistence risk for its constituency (NCSC Switzerland / GovCERT.ch, 2026-09-07). Any public body or supplier running a storefront, ticketing portal or fee-payment system on this platform (tourism boards, cantonal shops, public-transport ticketing among them) is in the affected population even without a Swiss-specific victim yet reported.

Triage: the exploitation trigger is Magento's own "Payment Transaction Failed Reminder" email, so an unexplained burst of these messages (especially containing unresolved template placeholders or Magento's template-error fallback text) is a Magento-specific tell that costs no additional tooling to check; legitimate declined-payment traffic can produce the same notification, so treat the burst as a lead, not a confirmation. On the network side, a web-tier host that only ever needs outbound HTTPS suddenly emitting repeated small UDP datagrams to port 123 is not a legitimate NTP client, which issues a single periodic query rather than a burst of server-mode replies; filtering by process name alone is insufficient once an implant has renamed itself to match the very daemon a defender would otherwise exclude from suspicion.

Sansec is publishing early because stores are being compromised right now.

Sansec Forensics Team 2026-09-05

Adobe is aware of CVE-2026-75650 being exploited in the wild.

Adobe PSIRT (APSB26-146) 2026-09-07

The fix ships as a hotfix, not as a full release.

Moving sessions to Redis or the database does not stop the attack. One merchant reported an attempt that failed against session storage and, eight seconds later, a second attempt that succeeded by using a file uploaded through Magento's custom options instead.

Sansec Forensics Team 2026-09-05

Successful exploitation allows unauthenticated attackers to achieve remote code execution and establish persistent backdoors on affected e-commerce servers via network access.

NCSC Switzerland / GovCERT.ch, Cyber Security Hub 2026-09-07
vulnerability08 Sep 04:39Zmulti-sourceOpen finding ↗