skip navigation
skip mega-menu

StyleSmuggler: How Aware responded to the Magento and Adobe Commerce security threat within six hours

A critical vulnerability in Magento Open Source and Adobe Commerce was actively exploited. Here’s what happened, what merchants need to check, and how our team responded.

When a security issue affects an eCommerce platform, speed matters. For a retailer, its website is where customers browse, pay and share their information. A serious vulnerability can put all of that at risk.

In September 2026, security researchers at Sansec - experts in eCommerce security disclosed StyleSmuggler, tracked as CVE-2026-75650. The vulnerability allowed attackers to execute code on a Magento Open Source or Adobe Commerce store without any access. Adobe rates this form of vulnerability as critical, with a CVSS score of 10.0, and has confirmed that it has been exploited in the wild. 

At Aware, we addressed the issue within six hours and continued monitoring afterwards. 

That rapid response matters, but this incident also shows why a security fix needs more than a patch: merchants must establish whether anyone accessed their store before the fix was applied.

What is StyleSmuggler?

StyleSmuggler is a vulnerability in the way Magento processes certain template data. In plain English, it creates a route for an unauthenticated attacker to make a vulnerable store run malicious code.

Sansec first observed attacks on 4 September 2026. Adobe released an emergency hotfix on 7 September. That gap is significant: stores could have been targeted before a fix was available. Sansec has since documented attackers changing their methods and using different tools after gaining access. 

Adobe’s security bulletin lists affected versions across Adobe Commerce, Adobe Commerce B2B and Magento Open Source, including supported 2.4.4 to 2.4.9 releases. Merchants should check their exact product, version and hotfix status, rather than assume that a recent routine update covers this vulnerability. 

How Aware responded

Our team treated StyleSmuggler as an urgent platform security issue. We resolved the issue within six hours of being notified about the vulnerability, then kept monitoring rather than treating the initial fix as the end of the job.

Applying Adobe’s hotfix closes the known vulnerability, but it does not automatically reveal or remove malicious code if an attacker reached a store earlier. Sansec explicitly advises merchants to scan for compromise as well as patch. 

For merchants, a strong response has two parts: fix the route in and investigate whether it was used. Monitoring remains important because new information about attack activity and indicators can emerge after the first advisory.

Andy, our founder, says:

Considering the vulnerability occurred out of hours, the team responded instantly to address any sites that could have been affected. Luckily, our hosting solution offers protection out of the box. I don't think we could have responded more effectively, and I'm very proud of all the steps the team took out of hours.

Why this is a serious issue for eCommerce businesses

Remote code execution is one of the most severe outcomes a software vulnerability can allow. In this case, Adobe says an attacker does not need an account to exploit the flaw. Sansec’s investigation describes attackers deploying backdoors and other tools on compromised stores. 

For a merchant, the potential impact extends beyond a technical incident. A compromised store may require an investigation into systems, credentials and integrations, alongside decisions about customer protection and business continuity. The exact impact depends on what happened on that particular store; the existence of the vulnerability alone does not mean every affected website was breached.

What Magento and Adobe Commerce merchants should do now

If your store may be affected, these are the priorities:

Confirm the Adobe hotfix is installed. Check the correct fix for your product and version, and verify that it has applied successfully. Adobe lists the StyleSmuggler hotfix as a priority 1 update. 

Investigate for signs of compromise. Review relevant logs and indicators, and use appropriate security scanning. A successful patch does not establish that a store was clean beforehand. 

Review credentials if compromise is suspected or confirmed. Adobe’s guidance, as reported by Sansec, includes rotating the encryption key and credentials it protects. That work needs to be handled carefully across connected services, not just inside Magento. 

Monitor. Security researchers have documented changes in attacker behaviour since the first attacks. Continue reviewing alerts and new guidance after the immediate fix. 

Security is an ongoing responsibility

StyleSmuggler is a reminder of how quickly a platform issue can become a live risk for retailers. The vulnerability was being exploited before Adobe’s emergency hotfix was published, and the response required both urgency and continued attention.

At Aware, we fixed the issue within six hours and kept monitoring, even out of hours. If you run Magento Open Source or Adobe Commerce and are unsure whether your store has been patched or checked for compromise, get in touch with our team. We can help you establish your status and work through the next steps.

Subscribe to our newsletter

Sign up here