← Back to Feed
StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
CVE-2026-75650
September 8, 2026 · Tenable Blog · Severity: CRITICAL
This article answers frequently asked questions about CVE-2026-75650, a zero-day remote code execution vulnerability in Adobe Commerce and Magento Open Source that has been actively exploited since September 4. It details the vulnerability's severity, affected versions, and the availability of a hotfix from Adobe. 📌 **Analyst Note:** The pre-patch exploitation window highlights the need for rapid response; merchants should apply the hotfix immediately and rotate encryption keys as recommended to prevent further compromise.
Key Takeaways
- CVE-2026-75650 is a critical unauthenticated remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source with a CVSS score of 10.0 and changed scope.
- Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different attack campaigns.
- Adobe released Hotfix VULN-39341 on September 7, 2026, and Tenable detection plugins will be published as they become available to help identify compromised systems.