Two Magento Security Updates in 24 Hours: What Merchants Need to Know

Security Patch

Magento and Adobe Commerce merchants have had a busy few days.

On September 7, Adobe released an emergency hotfix for StyleSmuggler (CVE-2026-75650), a critical unauthenticated remote code execution vulnerability already being exploited in the wild.

One day later, on September 8, Adobe released its scheduled September 2026 security update (APSB26-138), addressing a separate set of vulnerabilities across Adobe Commerce and Magento Open Source.

The important part:

These are two separate security updates. Applying the September security release does not replace the StyleSmuggler hotfix. Adobe recommends applying both.

First: the StyleSmuggler emergency hotfix

tyleSmuggler was disclosed by Sansec after the company detected active exploitation beginning on September 4.

The vulnerability, now tracked as CVE-2026-75650, has a maximum CVSS score of 10.0.
It allows an unauthenticated attacker to reach Magento’s template processing system and potentially execute arbitrary code on the server.

Adobe classified the fix as Priority 1, its highest patching priority, and released the VULN-39341 hotfix on September 7.

Affected supported branches include:

Adobe Commerce 2.4.4 through 2.4.9

Magento Open Source 2.4.6 through 2.4.9

Adobe Commerce B2B releases associated with the affected Commerce versions

Older releases within these branches are affected as well, and Adobe has published version-specific hotfix packages.

Then came the September security update

On September 8, Adobe published APSB26-138, its scheduled September security update.

This is not an updated StyleSmuggler patch.

It addresses a different group of vulnerabilities including:

  • Stored Cross-Site Scripting (XSS)
  • Incorrect authorization issues
  • Path traversal
  • Privilege escalation
  • Security feature bypass

 

Several of the vulnerabilities can be exploited without authentication, including two stored XSS vulnerabilities rated CVSS 9.3.
Adobe states that it is currently not aware of exploitation in the wild for the vulnerabilities covered by APSB26-138.
The update moves affected installations to the September security release line, including versions such as:

2.4.9-2026-sep
2.4.8-2026-sep
2.4.7-2026-sep

with corresponding releases for supported Adobe Commerce branches.

But there is one particularly important note in Adobe’s bulletin:

The CVE-2026-75650 hotfix must be applied in addition to the September security updates.

In other words, seeing a September 2026 Magento security patch applied does not automatically mean the store is protected against StyleSmuggler.

Patching StyleSmuggler is only part of the response

This is where StyleSmuggler differs from a normal security patch.

The vulnerability was being actively exploited for approximately three days before Adobe’s official hotfix became available.

That means a vulnerable store could already have been compromised before it was patched.

Sansec’s investigation, updated again on September 9, shows that attackers have been rapidly changing their payloads and persistence mechanisms.

Observed malicious processes have included names designed to look legitimate, such as:

kworker
fc-cache
chronyd

Sansec has also identified a second attacker using the StyleSmuggler entry point to deploy a PHP web shell under pub/media.

So applying the patch closes the vulnerability, but it does not remove a backdoor that may already exist.

What Magento and Adobe Commerce merchants should do now

For environments that may have been exposed, we would treat this as more than a routine Magento patch deployment.

The current remediation path is:

1

Apply the StyleSmuggler VULN-39341 hotfix.

2

Apply the September 2026 security update.

3

Verify that the StyleSmuggler hotfix was successfully applied.

4

Check the environment for indicators of compromise.

5

Rotate the Magento encryption key.

6

Rotate credentials that may have been exposed.

Adobe specifically recommends rotating associated credentials rather than only changing the Commerce encryption key.

That can include:

  • Admin passwords
  • REST, SOAP and GraphQL integration tokens
  • OAuth secrets
  • Payment gateway credentials
  • Database credentials
  • SSH and deployment keys
  • Shipping, tax and other third-party API credentials

 

Adobe warns that rotating the encryption key alone does not invalidate credentials an attacker may already have obtained.

Why this one deserves extra attention

Magento merchants are used to regular security releases.

StyleSmuggler is different.

It was a zero-day being actively exploited before an official fix existed, it requires no authentication, and the attackers behind the campaign have already demonstrated that they can change techniques quickly.

The September security release is also important — but it should not create a false sense of security around CVE-2026-75650.

As of September 9, the correct position is simple: both updates matter, and stores that were exposed before the emergency hotfix should also be checked for compromise.

For Magento and Adobe Commerce teams, this is one of those occasions where confirming that a patch deployment completed successfully isn’t enough. The state of the environment before the patch matters too.

If you’re unsure whether your Magento or Adobe Commerce installation has both updates applied, or whether it may have been exposed before the StyleSmuggler hotfix became available, Foxycom can help review the environment, patch status and remediation requirements.

 

Not sure if your Magento store is fully protected against StyleSmuggler?

We can review your Adobe Commerce or Magento environment, confirm whether the required patches are in place, and check for signs of compromise or risky configuration left behind after the vulnerability window.

No pitch. No obligation.