Cyber News / Article / Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source

Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
Home>Blog>Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
GabiSharadin
Sep 10, 20262 min read
TL;DR:CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and achieve remote code execution. Adobe assigned the vulnerability a CVSS score of 10.0 and released an emergency hotfix after exploitation was observed in the wild. Imperva Cloud WAF and On-Prem WAF customers are protected against exploitation attempts associated with CVE-2026-75650.
StyleSmuggler is an improper neutralization vulnerability in Magento’s template engine. Attackers can abuse the processing of styles properties to smuggle malicious PHP code past existing safeguards and into content that Magento later renders.
The attack occurs in two stages. First, the attacker sends a crafted request that causes malicious PHP code to be stored within Magento-generated content, such as a failure report. The attacker then triggers application functionality that renders the poisoned content, including Magento’s standard failed-payment email process. When the template is rendered, the injected PHP executes on the server.
No authentication or user interaction is required. The recipient does not need to open the failed-payment email, and the attack can succeed even if the email is never delivered. Successful exploitation gives the attacker arbitrary code execution in the context of the Magento application, potentially enabling malware deployment, persistent access, credential theft, payment-data compromise, or further movement within the environment. The vulnerability affectssupported versionsacross multiple Adobe Commerce and Magento Open Source branches, including systems that had received recent security patches.
Observed post-exploitation activity has included the deployment of persistent Linux backdoors disguised as legitimate processes such as kworker, fc-cache, and chronyd. Researchers have also identified a separate campaign using the vulnerability to install a PHP web shell, demonstrating that multiple threat actors are already attempting to operationalize StyleSmuggler.
Imperva has observed exploitation activity targeting websites across 15 countries, indicating that StyleSmuggler scanning and attack attempts are already geographically widespread. The United States accounts for 25% of targeted sites, followed by Mexico at 15.9%, Spain at 14%, and Singapore at 13.6%.
Retail websitesrepresentthe largest share of observed targets at 39.5%, consistent with Magento’s extensive use across ecommerce environments. Lifestyle sites account for another 19.5% of targets, followed by healthcare at 17.9%.
Attack traffic has primarily automated attacks. While client identifiers can be modified or spoofed, their prevalence is consistent with attackers using scripted tools to automate scanning and exploitation rather than interacting through conventional web browsers.
Imperva protections are actively identifying and blocking malicious requests associated with the StyleSmuggler attack chain before they can reach protected applications.
CVE-2026-75650 poses an immediate risk: it enables unauthenticated remote code execution, has already been weaponized, and can give attackers direct control over ecommerce servers. Adobe Commerce and Magento Open Source administrators should apply the VULN-39341 hotfix immediately and investigate potentially exposed systems for signs of compromise. As exploitation began before a patch was available, applying the hotfix does not remove malware or persistence mechanisms that may already be present.
Imperva Cloud WAF and On-Prem WAF customers are protected against exploitation attempts associated with StyleSmuggler.Imperva will continue monitoring the campaign as attackers refine their payloads and additional activity emerges.
Protect your business for 30 days on Imperva.
Protect your business for 30 days on Imperva.
RonMasas
Aug 10, 20268 min read
MulyLevy
Aug 10, 20264 min read
GabiSharadin
,MulyLevy
Jul 24, 20263 min read
BarMenachem
,MulyLevy
Jul 18, 20262 min read
YohannSillam
Jul 1, 20264 min read
ImpervaThreat
Jun 23, 20264 min read
Cookie PreferencesTrust CenterModern Slavery StatementPrivacyLegal
Cookie PreferencesTrust CenterModern Slavery StatementPrivacyLegal
Copyright © 2026 Imperva. All rights reserved
Related articles
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
3 days ago
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
5 days ago
Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5
21 days ago
You might Also like
Hackers Use Claude AI Agents to Automate Cyberattacks, Develop 0-Days and Evade Detection

New Android malware encrypts files, steals data, and harasses victims

