Magento and Adobe Commerce operators face an actively exploited unauthenticated RCE

BRIEF
A critical vulnerability identified as CVE-2026-75650 affects Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. The flaw is described as an unauthenticated remote-code-execution issue, meaning an attacker may not need a valid account before attempting to run code on an exposed store. Exploitation was reportedly observed from September 4, before Adobe released a hotfix on September 7. Multiple victim stores and attack campaigns were reported by researchers, but the supplied material does not establish the full number of affected organizations or the breadth of the activity. The issue has been given the name “StyleSmuggler” in research coverage; that label does not by itself describe the exploit’s technical cause. Store operators should treat internet-facing installations as urgent investigation targets, especially where patching was delayed during the exposure window. Applying the vendor hotfix is necessary, but it should not replace an examination for prior compromise. Teams should review web-server, application, administrative, payment, and hosting logs for unexpected requests, file changes, new accounts, altered extensions, and outbound connections. If compromise is suspected, isolate the system carefully, preserve evidence, rotate secrets from a trusted environment, and validate the integrity of payment and customer-data workflows before returning to normal operation.
WHY IT MATTERS
An unauthenticated code-execution flaw in an online-store platform can give attackers a direct path from a public service to the server running business logic and customer-facing functions. The reported pre-patch exploitation window means installing the fix now may not remove persistence or web shells already placed on a system. E-commerce teams also have to consider payment integrations, customer information, administrator credentials, and connected fulfillment services. The supplied reporting confirms active exploitation was observed, but it does not establish that every exposed store was targeted or compromised.