Adobe Magento CVE-2026-75650 Just Hit CISA’s Exploited List

Adobe Magento CVE-2026-75650 Just Hit CISA’s Exploited List

September 9, 2026
MicroSky Team
Microsky Blogs

If your NYC shop still runs Adobe Commerce or Magento Open Source on a public storefront, yesterday’s CISA listing is the one that matters for the box that takes cards. Adobe Magento CVE-2026-75650 (tracked by researchers as StyleSmuggler) is an unauthenticated template-engine flaw that Adobe rates CVSS 10.0. Adobe’s bulletin says it is already exploited in the wild. CISA added it to the Known Exploited Vulnerabilities catalog on September 8, 2026, with a federal remediation due date of September 11.

This is not another edge-appliance story like SonicWall SMA1000 on CISA’s exploited list, and it is not the RMM hotfix we covered for N-central CVE-2026-86218. Magento is the register, the catalog, and often the payment-token vault for a Staten Island retailer, a Midtown boutique, or a Brooklyn brand that grew past Shopify DIY. When unauthenticated code execution lands on that storefront, customer data and payment integrations are in play the same day.

What Adobe Magento CVE-2026-75650 actually is

Per Adobe Security Bulletin APSB26-146 (published September 7, 2026, Priority 1), the issue is CWE-1336: improper neutralization of special elements used in a template engine. Impact is arbitrary code execution. Authentication is not required. CVSS base score is 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Adobe states plainly that it is aware of exploitation in the wild.

Affected lines, from the same bulletin and Adobe’s Commerce knowledge-base article:

  • Adobe Commerce 2.4.4 through 2.4.9 (including August 2026 releases and earlier in each branch)
  • Adobe Commerce B2B 1.3.3 through 1.5.3
  • Magento Open Source 2.4.6 through 2.4.9 (Adobe’s bulletin table lists 2.4.9–2.4.6 for Open Source)

The fix ships as hotfix VULN-39341, not a full quarterly release. Adobe’s merchant article tells operators to apply the composer patch for their version and then rotate encryption keys and every credential that key protected.

Why CISA put it on the KEV list now

On September 8, 2026, CISA’s alert “CISA Adds Four Known Exploited Vulnerabilities to Catalog” listed CVE-2026-75650 alongside two Microsoft Windows privilege-escalation zero-days and N-central CVE-2026-86218. The KEV entry’s short description matches Adobe’s: improper neutralization in a template engine that can allow arbitrary code execution. Due date for federal agencies: September 11, 2026. Forensic triage is marked Yes under BOD 26-04 — meaning agencies must check whether the asset was compromised before the patch, not only whether the package version looks current.

CISA encourages private organizations to prioritize KEV items the same way. For a public Magento storefront, that is not a policy footnote. It is a three-day clock from the listing.

What Sansec and industry reporting already saw

E-commerce security firm Sansec published a StyleSmuggler analysis stating first confirmed exploitation on September 4, 2026 — three days before Adobe’s hotfix. Sansec reports the chain injects into Magento’s template path (including via styles properties) and can complete without an admin login. They reproduced the unauthenticated chain on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9, and noted a victim already on 2.4.6-p15 with July and August 2026 patches applied.

BleepingComputer (September 8) summarizes the same campaign: Sansec observed attacks planting a Linux backdoor whose C2 traffic was disguised to look like NTP, plus a second, unrelated actor dropping a small PHP web shell under the product image cache. Both outlets stress that patching alone does not clean a store that was hit before VULN-39341 existed.

We are not reproducing exploit steps here. The operational takeaway is blunt: if the store was internet-reachable between September 4 and the moment you applied the hotfix, treat compromise as possible until a Magento-aware scan and log review say otherwise.

What NYC SMBs should do this week

  1. Inventory the storefront. Confirm whether you run Adobe Commerce, Adobe Commerce B2B, Magento Open Source, or a hosted Magento SaaS where the vendor patches for you. Self-hosted and agency-managed boxes are the ones that lag.
  2. Apply VULN-39341 now. Follow Adobe’s version-specific composer hotfix from APSB26-146 / the Commerce KB article. Confirm with vendor/bin/magento-patches -n status (or your host’s equivalent) that patch 39341 shows Applied.
  3. Rotate secrets at the source. Adobe’s checklist is explicit: encryption key, Admin passwords, REST/SOAP/GraphQL integration tokens, OAuth client secrets, payment-gateway API credentials (Stripe, Braintree, Adyen, PayPal, and the rest), database credentials, SSH/deploy keys, and third-party extension API keys. Rotating the Magento encryption key alone does not invalidate anything an attacker already copied.
  4. Hunt before you declare clean. Sansec’s public indicators include unexpected “Payment Transaction Failed Reminder” bursts, suspicious processes mimicking fc-cache / chronyd / kworker, odd cron entries, and PHP files under pub/media. Use a Magento-aware malware scanner; do not stop at “version string looks new.”
  5. Tighten reachability. Put admin and staging behind VPN or IP allowlists. Keep the public catalog path, but stop exposing developer tools, unused GraphQL surfaces, and leftover staging copies on the open internet.

How this fits an MSP patch cadence

For MicroSky clients, Magento is often owned by a web agency while we own the Windows fleet, Microsoft 365, and the edge. That split is exactly where KEV storefront bugs slip. The practical workflow:

  • Tag every client asset that is Adobe Commerce / Magento in the inventory this week.
  • Open a joint ticket with the web vendor: hotfix applied, secrets rotated, malware scan completed, payment credentials rotated at the gateway console.
  • Screenshot or export proof of Applied status for 39341 and the credential-rotation checklist before you close the ticket.
  • If the store was live and unpatched after September 4, escalate to incident review — not a routine “patch completed” note.

Federal due dates are a useful forced calendar even when you are not an FCEB agency. September 11 is already tight for a store that still needs a maintenance window, a payment-credential rotation, and a malware pass.

Sources we opened for this post

  • Adobe Security Bulletin APSB26-146 — helpx.adobe.com
  • Adobe Commerce KB: Urgent Action Required (APSB26-146) — experienceleague.adobe.com
  • CISA alert, September 8, 2026 — four KEV additions including CVE-2026-75650
  • CISA KEV JSON entry for CVE-2026-75650 (dateAdded 2026-09-08, dueDate 2026-09-11)
  • Sansec: StyleSmuggler Magento / Adobe Commerce 0-day RCE under active attack
  • BleepingComputer: Adobe fixes critical Magento zero-day exploited to backdoor servers (Bill Toulas, September 8, 2026)

No invented infection counts for NYC. No exploit recipes. If your Magento box is still on an August 2026 build without VULN-39341, treat this as an emergency storefront ticket, not a quarterly chore.

Need a Magento / Adobe Commerce triage for your NYC storefront? Call MicroSky Managed Services at (718) 672-2177 or visit https://microskyms.com.

Want help applying this to your business?

MicroSky provides managed IT, cybersecurity, and web services for NYC businesses. If you want a clear plan and a responsive team, let's talk.

Newsletter

Stay on Top of Tech. Subscribe Today.

    Adobe Magento CVE-2026-75650 Just Hit CISA’s Exploited List | MicroSky Blog | MicroSky Managed Services, Inc.