Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for StyleSmuggler Magento and Adobe Commerce zero-day CVE-2026-75650 rated CVSS 10.0 under active exploitation — patch now

Magento Zero-Day Hits Online Stores — Patch Before You Open Today

A critical zero-day vulnerability dubbed StyleSmuggler is being actively exploited against Magento and Adobe Commerce stores. Security firm Sansec disclosed the flaw on 5 September after finding live attacks had already begun the day before. Adobe released an emergency patch (APSB26-146) on 7 September — two full days after exploitation started. The vulnerability, now tracked as CVE-2026-75650, carries a perfect CVSS 10.0 score.

StyleSmuggler affects every current version of Magento and Adobe Commerce, including fully patched 2.4.9 installations. The first confirmed victim was running 2.4.6-p15 with all August security patches applied — so being up to date didn’t help. Attackers don’t need any credentials. They abuse Magento’s own template rendering and email systems to plant a persistent backdoor that disguises itself as a Linux kernel thread. Across our client base in Sydney and regional NSW, we see Magento powering online ordering for hospitality venues, NFP donation pages, and retail stores. If you’re running Magento, this one’s as serious as it gets.

Download Adobe’s VULN-39341 composer patch from repo.magento.com and apply it immediately. If you can’t patch right now, disable GraphQL on any store that doesn’t use a headless or PWA front-end — most classic Magento themes don’t need it. As a belt-and-braces measure, disable PHP’s proc_open function and mount /tmp with noexec to stop the dropper executing its payload.

Not sure whether your site runs Magento, or need a hand applying the patch? Get in touch with our team — we can check your store and have it sorted today.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →