Skip to content
Web design for aspiring Tasmanian businesses in all corners of the state.
★★★★★ Rated 4.8 on Google Request a chat

Security notice

Adobe Commerce and Magento stores under active attack

Critical 10 September 2026 · Australian Signals Directorate, Cyber.gov.au

CVE-2026-75650 scores a full 10.0 and lets an attacker run code on an Adobe Commerce or Magento Open Source store without logging in. It was exploited before a patch existed, Adobe has since shipped one, and the ASD says a substantial number of potentially vulnerable instances are in Australia. If you run one of these stores, patch it today.

What's happening

A vulnerability in Adobe Commerce and Magento Open Source, tracked as CVE-2026-75650, scores 10.0 out of 10. It is an injection flaw in the platform's template engine, and it lets an attacker who has never logged in run their own code on the server. There is no account to guess and no setting to get wrong. If the store is reachable and unpatched, it is exploitable.

The Dutch security firm Sansec disclosed it on 5 September 2026 and named it StyleSmuggler. Attacks were already underway by then, with exploitation observed from 4 September, so store owners had no patch to apply for the first few days. Adobe has since published the fix as bulletin APSB26-146.

On compromised stores, attackers have installed a Rust based Linux backdoor and a PHP dropper that writes a web shell, which gives them a way back in that survives the patch. Patching alone does not undo a break-in that already happened.

The reason this one has an Australian advisory attached is scale. The ASD's ACSC says it is aware of a substantial number of potentially vulnerable instances in Australia and is telling organisations to patch as soon as possible.

You can read the original advisory on the ASD's Cyber.gov.au site.

Who is at risk

What to do if you run one of these stores

How this affects our clients

It does not. We do not build or manage Adobe Commerce or Magento stores, and no site we look after runs on either platform. We are publishing this because the ASD says a substantial number of vulnerable stores are Australian, and some of the people who read these notices will own one or know someone who does.

The wider point is the one we keep making. A platform with a large amount of server side code, a plugin ecosystem and an admin login exposed to the internet gives an attacker somewhere to aim. This flaw needed no password and no misconfiguration, only a reachable store. Jigsaw sites have no such runtime to exploit, which is the whole reason we build that way.

If you run a store on one of these platforms and want a second opinion on whether it has been touched, request a chat. We will tell you honestly if it is outside what we do.


Corey Crowden
Corey Crowden Creative and Technical Lead (And director of Tas Web Co)
Back Return to all notices

Crafting websites for aspiring businesses.