← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 8, 2026 · 14:00via Tenable Blog

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

Brief

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.

Key takeaways

  • CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.
  • Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different attack campaigns.
  • Adobe released Hotfix VULN-39341 on September 7, 2026, and Tenable detection plugins will be published as they become available.
Read more on Tenable Blog