ASD warns Aussie Adobe Commerce and Magento stores under attack

Key points

A critical vulnerability tracked as CVE-2026-75650, rated 10.0 on the CVSS scale, allows unauthenticated remote code execution on Adobe Commerce and Magento Open Source.

ASD warns Aussie Adobe Commerce and Magento stores under attack

ASD warns Aussie Adobe Commerce and Magento stores under attack

Key points

  • A critical vulnerability tracked as CVE-2026-75650, rated 10.0 on the CVSS scale, allows unauthenticated remote code execution on Adobe Commerce and Magento Open Source.
  • Sansec, which discovered and named the bug StyleSmuggler, said exploitation began on September 4, giving attackers around three days before Adobe shipped a hotfix.
  • ASD’s ACSC is aware of a substantial number of potentially vulnerable instances in Australia and advises organisations to patch as soon as possible.




ASD warns Aussie Adobe Commerce and Magento stores under attack










The Australian Signals Directorate has sent out a critical alert about a vulnerability in the Adobe Commerce and Magento Open Source ecommerce platforms that many stores in the country run for their online businesses.

Tracked as CVE-2026-75650 and rated 10.0 on the CVSS scale, the vulnerability is an improper neutralisation of special elements used in a template engine, leading to unauthenticated remote code execution.

ASD’s Australian Cyber Security Centre (ACSC) said in its alert.that exploitation requires the /graphql endpoint to be exposed.

The attack chain never touches an obvious injection point, instead manipulating “styles” properties in a GraphQL request to slip PHP code past input sanitisation and into a file the platform writes during normal operation, such as a payment failure report.

It is not clear how many stores in Australia are at risk, or have already been attacked, but ACSC said it is aware of “a substantial number of potentially vulnerable instances” locally.

Dutch ecommerce security firm Sansec discovered the bug, named it StyleSmuggler, and said exploitation began on September 4, with the first confirmed compromise at 22:20 UTC.

It published on September 5 before completing its analysis, at a point when Adobe had issued neither a CVE identifier nor an advisory.

“Sansec is publishing early because stores are being compromised right now,” the company said.

Attackers had around three days to break into stores before Adobe shipped a hotfix for the vulnerability.

ASD advises organisations to review their networks and environments for vulnerable versions of the ecommerce platforms, review mitigation advice, and to apply patches as soon as possible.

Users who have Adobe Commerce and Magento managed by third parties such as an MSP or enterprise IT provider should contact them to ensure the software has been patched, and monitor for suspicious activity. 

Adobe’s guidance advises merchants to rotate the Magento encryption key and the credentials it protected.

It also warned that patching stores during the three-day window of opportunity before the hotfix became available would not remove implants placed by attackers on systems.

The United States Cybersecurity and Infrastructure Security Agency (CISA) has added the bugs to its Known Exploited Vulnerabilities (KEV) catalogue.

In just over two years, the ecommerce platform has suffered three serious flaws that don’t require authentication to exploit: CosmicSting (CVE-2024-34102), which Sansec linked to 4275 confirmed store breaches, and SessionReaper (CVE-2025-54236), which saw mass exploitation last October when 62 percent of stores were still unpatched six weeks after the fix shipped.



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.