Background

CVE-2026-75650: StyleSmuggler — Critical RCE in Adobe Commerce and Magento

September 14, 2026 by Akamai Security Intelligence Group

Share

Key takeaways

We have been tracking a critical, unauthenticated remote code execution (RCE) vulnerability (tracked as CVE-2026-75650 and dubbed StyleSmuggler). Adobe Commerce and Magento Open Source are actively exploiting this vulnerability.

The vulnerability carries a maximum CVSS score of 10.0 and requires no authentication or user interaction to exploit.

Attackers smuggle malicious PHP code into Magento’s template-processing chain via HTTP headers and parameters, later executing it during automated email rendering.

Based on our investigation, Akamai Adaptive Security Engine (ASE) CMD Injection protections already block the primary GraphQL header- and parameter-based exploitation vectors natively, requiring no new rule deployment.

We continue to validate detection coverage across all observed exploitation vectors for this vulnerability.

Affected customers should still apply Adobe’s official hotfix (APSB26-146/VULN-39341) as soon as possible.

Vulnerability details

CVE-2026-75650 is a critical remote code execution vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. The flaw allows an unauthenticated attacker to inject PHP code into the platform’s template engine, and later execute it on the server.

The vulnerability has been actively exploited in the wild since early September 2026, prompting Adobe to release an emergency, out-of-band security update.

How the StyleSmuggler attack works

The attack unfolds in four steps:

  1. An attacker sends a request to Magento’s GraphQL endpoint with malicious PHP code hidden inside an HTTP header or parameter.

  2. Magento logs the unrecognized value, unintentionally storing the attacker’s PHP code in a server-side log file.

  3. A follow-up request triggers Magento’s template engine, commonly through generating a standard transactional email.

  4. During rendering, the template engine loads the poisoned log file and executes the embedded PHP code, granting the attacker remote code execution.

Because exploitation requires no authentication nor user interaction, any exposed, unpatched instance is at risk.

The vulnerability is present in Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9, and Adobe Commerce B2B 1.3.3 through 1.5.3. Users should apply the security updates provided by Adobe in APSB26-146 (hotfix VULN-39341) to remediate this vulnerability.

Mitigation with Akamai App & API Protector

Based on our investigation, Akamai App & API Protector’s Adaptive Security Engine CMD Injection protections natively block the primary GraphQL header- and parameter-based exploitation vectors, without requiring any new rule. Existing ASE rules already detect and stop the PHP/command-injection patterns used in the observed StyleSmuggler exploitation attempts that we analyzed. No public, fully weaponized proof of concept has been observed for this vulnerability as of this writing.

We continue to validate detection coverage across all observed and emerging exploitation vectors for this vulnerability. While Akamai web application firewall (WAF) protections can identify and block known exploit patterns, the most effective defense continues to be prompt application of the vendor patch. Given this issue’s severity, apply updates as soon as possible.

Stay tuned

The Akamai Security Intelligence Group will continue to monitor, report on, and create mitigations for threats such as these for both our customers and the security community at large. To keep up with more breaking news from the Akamai Security Intelligence Group, check out our research home page and follow us on social media.

About the Author(s)

Akamai Wave Blue

Akamai Security Intelligence Group

Akamai SIG is a global team of world-class researchers, engineers, strategists, and data scientists with a broad range of expertise and security disciplines. Our data sources include the enormous Akamai Cloud, open sources, collaboration with third parties, and dark web intelligence. We have also developed our own algorithms and tools that help us deliver our research and keep Akamai security solutions up to date.