ZeroHour
Story · 2 sources · 2 articlesfirst updated ()1

StyleSmuggler (CVE-2026-75650): Adobe Commerce/Magento zero-day RCE exploited since Sept 4, patched Sept 7, added to CISA KEV

What's new: First merged summary for this story. Over the covered window the story progressed from in-the-wild exploitation (September 4), to Adobe's hotfix VULN-39341/APSB26-146 (September 7), to vendor advisories from Tenable and Canada's Cyber Centre AV26-888 (September 8), to CISA adding CVE-2026-75650 to the KEV catalog and a second CCC advisory AV26-808 flagging CVE-2026-71362 (September 10), followed…
Merged summary · glm-5.3 · rewritten as coverage arrives

A CVSS 10.0 unauthenticated remote code execution zero-day in Adobe Commerce, Adobe Commerce B2B and Magento Open Source, exploited in the wild since September 4, 2026, was fixed by Adobe hotfix VULN-39341 on September 7 and added to CISA's Known Exploited…

CVE-2026-75650, dubbed StyleSmuggler, is a CVSS 10.0 unauthenticated remote code execution flaw in Adobe Commerce 2.4.4-2.4.9, Adobe Commerce B2B 1.3.3-1.5.3 and Magento Open Source 2.4.6-2.4.9 (per Tenable; Security Affairs cites Magento 2.4.7-2.4.9; Canada's Cyber Centre says versions prior to the August 2026 patch levels are affected). The flaw is exploited via malicious style properties that inject PHP code executed when Magento renders the Payment Transaction Failed Reminder transactional email. Active exploitation began September 4, 2026 — three days before Adobe shipped Hotfix VULN-39341 (APSB26-146) on September 7. Sansec and Disrex confirmed multiple victim stores across at least two distinct campaigns: one operator deployed a persistent implant at ~/.local/share/.gvfsd/gvfsd-user masquerading as kworker, fc-cache or chronyd, restored by a cron job (every five minutes, later twice hourly) and supporting x86-64 and arm64, while a second operator dropped a PHP web shell in product image caches. Tenable noted the flaw was not yet in CISA KEV as of September 8; on September 10 CISA added it to the KEV catalog alongside Windows privilege-escalation flaws CVE-2026-81963 and CVE-2026-85880 (CVSS 7.8 each) and N-able N-central pre-auth RCE CVE-2026-86218 (CVSS 10.0), with BOD 22-01 deadlines of September 11, 2026 for the non-Windows entries and September 22, 2026 for the Windows flaws. Adobe's wider release patched more than 170 vulnerabilities, including Campaign Classic command injection CVE-2026-82004 and critical ColdFusion RCE flaws CVE-2026-48273 and CVE-2026-75746, with per-product counts of Experience Manager (107), Acrobat Reader (32), Photoshop (8), plus Illustrator and Animate. Adobe and Sansec urge rotating encryption keys, admin passwords, API tokens and all source credentials. Akamai published further technical analysis on September 14. Related ecosystem developments: Canada's Cyber Centre (AV26-808 Update 1, September 10) flagged CVE-2026-71362 in Adobe Commerce as exploited in the wild per open-source reporting (tracked under APSB26-92), and Sansec reported that vendor Amasty patched dozens of Magento/Adobe Commerce extensions, including two critical unauthenticated web shell upload flaws in Advanced Product Reviews and Gift Card, with a related Order Attributes flaw previously seeing over 12,000 blocked exploitation attempts against 25% of Magento stores in three days.

  • CVE-2026-75650 (StyleSmuggler) is a CVSS 10.0 unauthenticated RCE exploited via malicious style properties injecting PHP code executed through the Payment Transaction Failed Reminder transactional email.
  • Affected versions per Tenable: Adobe Commerce 2.4.4-2.4.9, Adobe Commerce B2B 1.3.3-1.5.3, Magento Open Source 2.4.6-2.4.9; Security Affairs cites Magento 2.4.7-2.4.9 — sources disagree on the Magento Open Source lower bound.
  • Active exploitation began September 4, 2026, three days before Adobe released Hotfix VULN-39341 (APSB26-146) on September 7, 2026.
  • Sansec and Disrex confirmed multiple victim stores across at least two distinct campaigns; implants masquerade as kworker/u:8:0, fc-cache or chronyd at ~/.local/share/.gvfsd/gvfsd-user, restored by cron every five minutes (later twice…
  • Not in CISA KEV as of September 8 (Tenable); CISA added CVE-2026-75650 to KEV by September 10, 2026, together with Windows LPE flaws CVE-2026-81963 and CVE-2026-85880 (CVSS 7.8 each) and N-able N-central pre-auth RCE CVE-2026-86218 (CVSS…
  • BOD 22-01 deadlines for federal civilian agencies: September 11, 2026 for the non-Windows KEV entries, September 22, 2026 for the two Windows flaws.
  • Adobe's accompanying release fixed 170+ vulnerabilities: Campaign Classic command injection CVE-2026-82004, critical ColdFusion RCE flaws CVE-2026-48273 and CVE-2026-75746, plus Experience Manager (107), Acrobat Reader (32), Photoshop (8),…
  • Adobe recommends rotating encryption keys, admin passwords, API tokens and all protected credentials; prior Magento flaws SessionReaper, CosmicSting and CVE-2022-24086 all previously reached CISA KEV.

Coverage timeline

  1. · 7d ago
    Tenable Blog· 88
    StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

    Critical unauthenticated RCE zero-day CVE-2026-75650 (StyleSmuggler) in Adobe Commerce and Magento is actively exploited; Adobe shipped hotfix VULN-39341 on September 7.

  2. · 7d ago
    Canadian Centre for Cyber Security· 68
    Adobe security advisory (AV26-888)

    Canada's Cyber Centre warns CVE-2026-75650 in Adobe Commerce and Magento Open Source is exploited in the wild; hotfixes and updates are available.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-24086
Unauthenticated RCE via checkout input-validation flaw in Adobe Commerce/Magento

Adobe Commerce and Magento Open Source versions 2.4.3-p1 and earlier and 2.3.7-p2 and earlier contain an improper input validation flaw (CWE-20) in the checkout process. A remote attacker can trigger it with no privileges and no user interaction by submitting crafted input to a store's checkout flow, and successful exploitation results in arbitrary code execution on the server hosting the storefront. Any Adobe Commerce or Magento Open Source storefront running the affected versions is exposed, and because these are internet-facing e-commerce sites the practical exposure is broad. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15), its EPSS exploitation probability is 99.2% (100th percentile), and news reports describe ongoing attacks against Magento 2 stores, including recurring 'Xurum' attack campaigns and template-based attacks.

Do: Upgrade every store to an Adobe-patched release per the vendor's instructions - i.e., any release newer than 2.4.3-p1 on the 2.4.x line or newer than 2.3.7-p2 on the 2.3.x line - noting that headlines indicate companion Magento CVEs were fixed in the same patch release, so consult Adobe's advisory for the full list. Because exploitation is unauthenticated and confirmed in the wild, prioritize internet-facing shops; WAF rules may reduce risk, but reports indicate WAF bypasses in related Magento attacks, so patching is the only reliable fix. After patching, review web server and application logs for exploitation attempts against the checkout flow and check affected hosts for indicators of compromise.

9.899% KEV
  • Adobe Commerce 2.4.3-p1 and earlier; 2.3.7-p2 and earlier
  • Adobe Magento Open Source 2.4.3-p1 and earlier; 2.3.7-p2 and earlier
massroughly 100,000-300,000 online storefronts (Magento/Adobe Commerce is among the most widely deployed e-commerce platforms)
CVE-2024-34102
XXE vulnerability enabling RCE in Adobe Commerce and Magento Open Source

CVE-2024-34102 is an improper restriction of XML external entity reference (XXE) vulnerability (CWE-611) in Adobe Commerce and Magento Open Source, where the platform does not properly restrict external entities when processing XML, so an attacker who can submit crafted XML containing external entity references can have it parsed with attacker-controlled resources. XXE flaws classically enable local file disclosure and server-side request forgery, and in this case Adobe states the flaw allows remote code execution on the affected server. Any organization running a vulnerable Adobe Commerce or Magento Open Source storefront is affected, and because these are internet-facing e-commerce platforms that routinely process XML input, exposure is likely to be broad. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-17, confirming exploitation in the wild, and its EPSS score of ~100% (100th percentile) indicates near-certain near-term exploitation activity; no public proof-of-concept is known and CVSS has not yet been scored. CISA lists ransomware use as unknown, so a ransomware connection should not be assumed.

Do: Apply Adobe's security updates for Adobe Commerce and Magento Open Source per the vendor's June 2024 advisory (APSB24-40), or, per the CISA KEV required action, apply vendor-recommended mitigations or discontinue use of the product if patches are unavailable. Review any endpoints or integrations that accept XML from untrusted users and hunt for signs of XXE exploitation, such as unexpected outbound requests, anomalous file reads, or webshell artifacts. Continue monitoring Adobe and CISA KEV for updated mitigation guidance and remediation deadlines.

9.8100% KEV PoC
  • Adobe Commerce
  • Adobe Magento Open Source
mass≈150,000+ storefronts (public technology scans report on the order of 100k-250k live Magento-based sites)
CVE-2025-54236
Unauthenticated Session Takeover in Adobe Commerce and Magento (SessionReaper)

Adobe Commerce and Magento Open Source contain an improper input validation flaw (CWE-20), widely tracked as 'SessionReaper', that lets a remote, unauthenticated attacker take over user sessions. The flaw is exploitable over the network with no privileges and no user interaction (CVSS 3.1 9.1, critical). A successful attacker hijacks legitimate customer or admin sessions, yielding high confidentiality and integrity impact; a public writeup additionally describes unauthenticated exploitation potentially reaching code execution. Anyone running Adobe Commerce (including Commerce B2B) or Magento Open Source on the affected 2.4.x releases is exposed. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2025-10-24, reporting headlines cite over 250 observed attacks, EPSS is 94.5%, and roughly 3 in 5 stores were reported as still unpatched.

Do: Immediately upgrade every affected 2.4.x line to a release newer than 2.4.9-alpha2/2.4.8-p2/2.4.7-p7/2.4.6-p12/2.4.5-p14/2.4.4-p15 per Adobe's security advisory. Because the flaw is on CISA's KEV list, federal agencies must apply the vendor's mitigations (or BOD 22-01 cloud guidance) or discontinue use; other defenders should prioritize patching given 250+ observed attacks and 94.5% EPSS. Until patched, watch for indicators of session takeover — unexpected customer or admin sessions, unfamiliar admin accounts, and anomalous session activity — and review Adobe's advisory for interim mitigations.

9.195% KEV PoC
  • Adobe Commerce 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier (all listed 2.4.x lines and older releases)
  • Adobe Commerce B2B Listed via CPE as affected alongside Adobe Commerce; no separate version range given in the source data — treat B2B deployments on the affected Commerce 2.4.x l
  • Adobe Magento Open Source (Magento) 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier
mass≈100,000+ internet-facing Adobe Commerce/Magento storefronts (order of magnitude 10^5)
CVE-2026-48273
Eval Injection RCE in Adobe ColdFusion (CVSS 9.9, low-privileged attacker)

CVE-2026-48273 is a critical (CVSS 9.9) eval injection flaw (CWE-95) in Adobe ColdFusion in which untrusted input is not properly neutralized before it is placed into dynamically evaluated code. A remote attacker who has only low-privileged access to a vulnerable ColdFusion server can trigger the flaw over the network, with no user interaction required. Successful exploitation yields arbitrary code execution in the context of the current user, and the changed CVSS scope (S:C) indicates the impact can extend beyond the directly vulnerable component, a pattern typical of ColdFusion flaws that enable broader system-level code execution. All Adobe ColdFusion deployments are potentially affected; the source data does not specify affected version ranges, so admins should consult Adobe's bulletin for the exact versions fixed. As of this writing there is no known public proof-of-concept and the flaw is not in CISA KEV, though EPSS assigns a 1.7% probability of exploitation within 30 days; the fix shipped in Adobe's large recent patch batch, which also addressed three CVSS 10.0 ColdFusion and Campaign Classic flaws.

Do: Apply the Adobe ColdFusion security update covering this CVE from the current patch batch immediately on all ColdFusion servers, prioritizing any that are internet-exposed, and confirm your exact version against Adobe's bulletin since fixed versions are not listed here. Because only low-privileged access is required and no user interaction is needed, audit which accounts and request paths feed untrusted input into dynamically evaluated expressions and restrict or validate such inputs. No public PoC or known exploitation exists yet, so monitor Adobe advisories and threat feeds for updated indicators of compromise.

9.92%
  • Adobe ColdFusion
large~tens of thousands of internet-exposed ColdFusion servers (estimate; Adobe does not publish install counts)
CVE-2026-71362
Unauthenticated Privilege Escalation Flaw in Adobe Commerce (Magento)

CVE-2026-71362 is an incorrect-authorization flaw (CWE-863) in Adobe Commerce, the e-commerce platform formerly known as Magento, in which authorization checks are applied incorrectly and can be bypassed. It is triggered over the network without authentication or user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). A successful attacker gains elevated access to sensitive resources — a privilege-escalation condition that Adobe's APSB26-92 advisory and press coverage describe as an account-takeover risk. Any organization running an unpatched Adobe Commerce/Magento deployment is affected; exact version ranges are listed in Adobe security bulletin APSB26-92. The flaw came under active attack shortly after public disclosure, and its EPSS score of 25.1% (98th percentile) signals a high likelihood of continued near-term exploitation.

Do: Apply the fix released under Adobe advisory APSB26-92 immediately, prioritizing internet-facing Commerce/Magento instances, and check the bulletin for the exact patched version ranges for your deployment. Because exploitation requires no credentials or user interaction, review admin accounts, API integrations, and user/role assignments for unauthorized privilege changes, and restrict admin-panel and storefront API access where feasible. Monitor Adobe's advisory for indicators of compromise given confirmed in-the-wild exploitation.

9.125%
  • Adobe Commerce (Magento)
mass≈200,000+ Magento/Adobe Commerce storefronts worldwide
CVE-2026-7565
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including,

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, 4.1.4 via the 'import-user-file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

NVD description · AI analysis pending
4.9<1%
  • WordPress
CVE-2026-75650
Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CVE-2026-75650)

Adobe Commerce and Magento (including Adobe Commerce B2B) contain an improper neutralization of special elements used in a template engine (CWE-1336), a template-injection flaw that permits arbitrary code execution in the context of the current user. The flaw is reachable over the network by unauthenticated attackers, requires no user interaction, and its changed scope (CVSS 3.1 S:C) means injected code executes beyond the vulnerable component, producing a maximum-severity (CVSS 10.0) remote code execution condition. A successful attacker gains arbitrary code execution on the storefront server; in the observed campaign, intruders installed a Rust backdoor and a PHP web shell (dubbed 'StyleSmuggler') on compromised servers. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is in scope, with internet-facing e-commerce deployments most exposed. Exploitation is confirmed in the wild: the bug was abused as a zero-day before patching and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08.

Do: Apply Adobe's released patches immediately per vendor instructions, prioritizing internet-facing Commerce/Magento storefronts, and ensure compliance with CISA BOD 26-04 timelines for KEV entries. Hunt for 'StyleSmuggler' indicators of compromise, including unexpected Rust backdoor binaries and PHP web shells on hosts, and review template/theme customizations for tampering. Exact fixed version numbers are not included in the available data, so consult Adobe's advisory for the correct patched release for your Commerce/Magento version line.

10.02% KEV PoC
  • Adobe Commerce
  • Adobe Commerce B2B
  • Adobe Magento (open-source)
massroughly 100,000-300,000 internet-facing storefronts
CVE-2026-75746
SQL Injection Leading to Arbitrary Code Execution in Adobe ColdFusion

CVE-2026-75746 is an SQL injection flaw (CWE-89) in Adobe ColdFusion that can escalate to arbitrary code execution in the context of the current user. A remote attacker who has already obtained high-privileged access, such as administrative-level credentials, can trigger the flaw over the network without any user interaction, and the changed scope means the impact extends beyond the vulnerable component's normal security boundary. Successful exploitation carries high-impact confidentiality, integrity, and availability consequences for the server. Organizations running Adobe ColdFusion, particularly internet-facing instances or deployments where privileged access is reachable by less-trusted users, are in scope. As of this analysis there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates roughly a 1.1% chance of exploitation within 30 days, indicating no known exploitation to date.

Do: Apply the ColdFusion security update issued in Adobe's recent batch (which patched over 170 vulnerabilities) and confirm your installed build matches the fixed release listed in the Adobe advisory. Because the flaw requires high-privileged access, restrict administrative access to ColdFusion, rotate and harden privileged credentials, review logs for unexpected SQL activity from privileged accounts, and limit internet exposure of the server. No public PoC or KEV listing exists yet, but prioritize patching internet-facing ColdFusion instances given the critical base score.

9.11%
  • Adobe ColdFusion
largetens of thousands of internet-exposed ColdFusion servers (total installed base is larger but unreported)
CVE-2026-81963
+1 in the same advisory: …85880
Local Privilege Escalation via Link Following in Windows Update Stack

CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use.

Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems.

7.8<1% KEV
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2025
masswell over 1,000,000
CVE-2026-82004
Unauthenticated OS Command Injection in Adobe Campaign Classic

Adobe Campaign Classic (ACC) contains an OS command injection flaw (CWE-78) in which special elements passed to an operating system command are improperly neutralized, allowing attacker-supplied commands to run on the host. Per the CVSS vector, it is reachable over the network (AV:N), requires no privileges or user interaction, and has changed scope (S:C), meaning a successful attack can also affect resources beyond the vulnerable component. An attacker gains arbitrary code execution in the context of the current user, with high impact to confidentiality, integrity, and availability. Any organization running an affected Adobe Campaign Classic deployment is potentially exposed, though only instances reachable over the network are practically exploitable. No public proof-of-concept or confirmed in-the-wild exploitation is known, EPSS estimates a ~1.4% probability of exploitation within 30 days, and the fix arrived in a large Adobe patch release covering 170+ vulnerabilities.

Do: Upgrade Campaign Classic to the fixed build listed in Adobe's security bulletin for this CVE, since the affected and fixed version numbers are not included in the data provided. Until patched, limit network exposure of Campaign Classic application/web servers to trusted networks, as the flaw is exploitable without authentication or user interaction. Monitor for a public PoC or CISA KEV listing and review application service accounts for signs of unexpected command execution.

10.01%
  • Adobe Campaign Classic (ACC)
moderate~1,000-10,000 enterprise deployments worldwide (estimate; Adobe publishes no install counts)
CVE-2026-86218
Pre-Auth Static Code Injection RCE in N-able N-central (Exploited in the Wild)

CVE-2026-86218 is a static code injection flaw (CWE-96) in N-able's N-central on-premises remote monitoring and management (RMM) platform, carrying a maximum CVSS 4.0 score of 10.0. An unauthenticated, remote attacker triggers it by sending crafted network input to the N-central server that is improperly neutralized and persisted into application-managed code, which the server then executes — no privileges (PR:N) or user interaction (UI:N) are required. Successful exploitation yields full server compromise with high impact on confidentiality, integrity, and availability, and because N-central acts as the management hub for downstream customer endpoints, compromise can expose the entire managed estate. Any organization running an affected N-central release (before 2026.3.1.14) — primarily MSPs and corporate IT departments using N-able RMM — is affected. The flaw is confirmed exploited in the wild: N-able patched it as a zero-day, CISA added it to the KEV catalog on 2026-09-08, and it is the fourth N-central hotfix in five weeks, though no public PoC is known and ransomware use is unknown.

Do: Upgrade N-central to 2026.3.1.14 or later (or apply N-able's hotfix) immediately, as the flaw is in CISA's KEV catalog and BOD 26-04 timelines apply to federal stakeholders. Until patched, remove direct internet exposure of the N-central server (restrict to VPN/management networks via firewall allowlists) since no authentication is needed for exploitation. Because in-the-wild exploitation is confirmed, review internet-facing N-central servers for indicators of compromise such as unexpected processes, unusual child processes of the web service, and new or suspicious accounts.

10.0<1% KEV PoC
  • N-able N-central before 2026.3.1.14
large≈ tens of thousands of deployed/internet-exposed N-central servers (order of magnitude ~10k+), each managing many downstream customer endpoints