StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways CVE-2026-75650 is a critical remote…

devsecurity

Sources

Vulnerabilities

Why this score
Signals contributing to the severity score
SignalPoints
kev added50
kev short fuse — 3 days to remediate15
public poc — 5 repositories20