CVE-2026-75650 is a maximum-severity (CVSS 10.0) improper-neutralisation vulnerability in Adobe Commerce and Magento Open Source that allows unauthenticated remote code execution, tracked publicly as the "StyleSmuggler" chain. It is under active exploitation, has been used to backdoor online stores, and was added to the CISA Known Exploited Vulnerabilities catalogue on 8 September 2026 with a remediation deadline of 11 September.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-75650 |
| CVSS | 10.0 |
| Type | Unauthenticated remote code execution (improper neutralisation) |
| Affected | Adobe Commerce and Magento Open Source |
| KEV | Added 2026-09-08; CISA due date 2026-09-11 |
| ACSC | Critical alert 2026-09-09 โ "Active exploitation of Adobe Commerce and Magento Open Source vulnerability" |
The Australian Signals Directorate publicised the exploitation directly to Australian merchants, with iTnews reporting on 10 September that ASD has warned Australian Adobe Commerce and Magento stores are under attack. The Australian alert, not the US KEV date, is the operative obligation for Australian operators. This is the same StyleSmuggler chain covered in the 2026-09-10 digest, formalised as an ACSC Critical alert.