Adobe shipped an emergency patch on September 7 for a flaw in Adobe Commerce and Magento Open Source, the e-commerce platform behind a large share of mid-size online stores. The bug — tracked as CVE-2026-75650 and nicknamed "StyleSmuggler" by researchers — scores a perfect 10 out of 10 on the standard severity scale. No username or password is needed to exploit it, and by the time Adobe had a fix ready, attackers were already using it.
Most vulnerability disclosures follow a predictable order: someone finds a bug, reports it privately, the vendor patches it, then details go public. This wasn't that. The security firm Sansec found real attacks using this flaw in the wild starting around September 4 — three days before Adobe's patch shipped. Attackers were abusing a quirk in Magento's email-template system (the kind of thing that generates a "payment failed" notice) to smuggle in code and run it on the server, then dropping a backdoor for persistent access. That's a genuine zero-day: a live threat with no fix available yet, not a theoretical risk from an old CVE nobody patched.
If you're not sure whether your store's platform, plugins, and hosting are current — or whether "someone" is actually checking on a schedule — that's worth confirming rather than assuming. Zero-days like this one are exactly the scenario where "we'll get to it" turns into a much longer conversation.
Sources: