Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [cve, adobe-commerce, magento, stylesmuggler, rce, kev, active-exploitation, acsc] ยท confidence: high ยท severity: critical ยท affected_sectors: [retail, financial-services, technology] ยท au_impact: true

CVE-2026-75650 is a maximum-severity (CVSS 10.0) improper-neutralisation vulnerability in Adobe Commerce and Magento Open Source that allows unauthenticated remote code execution, tracked publicly as the "StyleSmuggler" chain. It is under active exploitation, has been used to backdoor online stores, and was added to the CISA Known Exploited Vulnerabilities catalogue on 8 September 2026 with a remediation deadline of 11 September.

Attribute Detail
CVE CVE-2026-75650
CVSS 10.0
Type Unauthenticated remote code execution (improper neutralisation)
Affected Adobe Commerce and Magento Open Source
KEV Added 2026-09-08; CISA due date 2026-09-11
ACSC Critical alert 2026-09-09 โ€” "Active exploitation of Adobe Commerce and Magento Open Source vulnerability"

The Australian Signals Directorate publicised the exploitation directly to Australian merchants, with iTnews reporting on 10 September that ASD has warned Australian Adobe Commerce and Magento stores are under attack. The Australian alert, not the US KEV date, is the operative obligation for Australian operators. This is the same StyleSmuggler chain covered in the 2026-09-10 digest, formalised as an ACSC Critical alert.