preloader

· · digital-security e-commerce magento adobe-commerce cve vulnerability-management patch-management europe

A Fully Patched Magento Store Got Backdoored Anyway. Here Is Why

Source: Sansec

The uncomfortable detail in this one is not the CVSS score, it is who got hit first.

An attack that needs no login and no user interaction

CVE-2026-75650, publicly named StyleSmuggler, is a zero-day in Magento Open Source and Adobe Commerce that requires no authentication whatsoever. Security firm Sansec spotted the campaign on September 4 at 22:40 UTC and reproduced the full attack chain within hours on clean installations of Magento 2.4.7, 2.4.8 and 2.4.9. The technique injects PHP code into Magento’s template system by abusing the platform’s own “styles” handling, then triggers execution through the store’s failed payment email, either by generating a failure report or by letting a genuine email delivery failure resend it. No admin panel access, no stolen credentials, no click from a victim, just a crafted request against the storefront itself.

Fully patched was not good enough

The detail that should worry every store operator: the first identified victim was running Magento 2.4.6-p15 with July and August 2026 security patches fully applied. Every advisory issued before September had already been addressed. StyleSmuggler exploited a flaw nobody had patched yet, because nobody had disclosed it yet, and it worked identically against a diligently maintained store and a neglected one.

Where the fix stands right now

Adobe published its emergency advisory, APSB26-146, on September 7 at 20:20 UTC, rated at the platform’s highest priority level. The fix ships as a hotfix rather than a full point release: a composer patch (VULN-39341-composer-patches.zip) from repo.magento.com that needs to be applied directly rather than waited for in the next scheduled update. Given that Sansec’s disclosure and Adobe’s hotfix are only hours apart at time of writing, a large share of the roughly 100,000 live Magento and Adobe Commerce stores worldwide, a meaningful number of them run by European retailers and agencies, are still unpatched.

What to do today if you run a Magento or Adobe Commerce store

Apply the composer patch now rather than scheduling it for a maintenance window, check your codebase for unfamiliar template modifications or unexpected changes to failed-payment email templates, and review recent admin and cron activity for anything that doesn’t match your team’s normal patterns. Compromise here is designed to be quiet: a planted backdoor that skims payment data or admin sessions can sit undetected for weeks if nobody goes looking.

If you run an e-commerce platform and need a second set of eyes on whether it has already been touched, or help applying and verifying this hotfix correctly, contact Excello Digital. We help European online retailers stay ahead of vulnerabilities like this one instead of finding out from a chargeback dispute.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!