Home / Companies / Fastly / Blog / Post Details
Content Deep Dive

What is Style Smuggler (CVE-2026-75650)?

Blog post from Fastly

Post Details
Company
Date Published
Author
Matthew Mathur
Word Count
1,093
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

Sansec identified CVE-2026-75650, an unauthenticated server-side template injection vulnerability in Adobe Commerce and Magento that can lead to remote code execution and was reportedly exploited before Adobe released partial fixes in APSB26-146 on September 7, 2026. Known as “Style Smuggler,” the attack chain uses several requests to place PHP code into a Magento log file, insert crafted template directives into a guest cart address, and trigger failed-payment email processing to instantiate arbitrary classes and include the poisoned log file. The vulnerability arises from template-filter behavior that can improperly propagate signed directives and from pre-patch handling that permits block directives to create classes beyond intended block types. Researchers noted that alternative methods and gadget chains may exist, while providing a Nuclei detection template tested against multiple Magento versions. Fastly has also issued an optional virtual patch designed to block each stage of the exploit chain and provide interim protection while organizations apply official updates.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.