On September 5, Sansec disclosed StyleSmuggler, an unauthenticated remote code execution vulnerability in Magento Open Source and Adobe Commerce, now tracked as CVE-2026-75650. It was being exploited in the wild before disclosure.
We won’t detail the specifics here for security reasons. Since September 5, we’ve rolled out the following across the platform:
- Request filtering for known StyleSmuggler exploitation patterns at the web application firewall.
- Tightened system-level firewall rules.
- Endpoint detection on affected nodes.
- Fleet-wide scans for known indicators of compromise. Affected customers have been contacted directly.
These are mitigations, not a fix. Adobe released hotfix VULN-39341 on September 8. Apply it. Adobe also recommends rotating your encryption key and all credentials it protected, including integration tokens and payment gateway keys.
We’re still monitoring and will keep adjusting rules as the payloads change. If legitimate traffic is being blocked, open a support ticket and we’ll sort it out.