Security alert: Update Magento and Adobe Commerce immediately
An urgent hotfix is available to patch a critical zero-day vulnerability in Magento and Adobe Commerce. Update your software as soon as you can.
A critical vulnerability in Adobe Commerce and Magento was already being exploited before a hotfix became available. If you haven't already acted against CVE-2026-75650, known as "StyleSmuggler", it is crucial that you do. A fix is available from Adobe.
StyleSmuggler is an unauthenticated remote code execution flaw, meaning that it gives attackers deep access to your store and customers' data, including credit cards. According to CrowdSec (with emphasis added):
Code execution on a Magento server means the attacker sits where card data is entered, customer records are stored, and the database password lives. Sansec found a Rust backdoor disguised as system processes that beacons to its operators over traffic shaped like time-sync (NTP) packets, and a second actor dropping a PHP web shell into the product image cache. That is the setup for card skimming and for reselling access to the store. CrowdSec CTI classifies 98% of the observed intent as infrastructure takeover.
Affected versions
Every version of Magento or Adobe Commerce that is currently in support is affected by StyleSmuggler.
-
Magento Open Source: 2.4.6 to 2.4.9.
-
Adobe Commerce: 2.4.4 to 2.4.9.
-
Adobe Commerce B2B: 1.3.3 to 1.5.3.
Anything older than the versions listed above is already out of support, and therefore vulnerable. The safest course of action is to update to a supported version before applying the hotfix.
To start taking action, see Adobe's security bulletin, including the hotfix.
Even if your server is managed, this is an application update for you to make
Whether your server is managed or unmanaged, this is an update that you need to make because it is beyond our control. Managed Services cover the entire infrastructure layer (like patching Linux vulnerabilities), but not the application layer.
Please apply the hotfix to Magento or Adobe Commerce as soon as you possibly can.