What is Style Smuggler (CVE-2026-75650)?
Blog post from Fastly
Sansec identified CVE-2026-75650, an unauthenticated server-side template injection vulnerability in Adobe Commerce and Magento that can lead to remote code execution and was reportedly exploited before Adobe released partial fixes in APSB26-146 on September 7, 2026. Known as “Style Smuggler,” the attack chain uses several requests to place PHP code into a Magento log file, insert crafted template directives into a guest cart address, and trigger failed-payment email processing to instantiate arbitrary classes and include the poisoned log file. The vulnerability arises from template-filter behavior that can improperly propagate signed directives and from pre-patch handling that permits block directives to create classes beyond intended block types. Researchers noted that alternative methods and gadget chains may exist, while providing a Nuclei detection template tested against multiple Magento versions. Fastly has also issued an optional virtual patch designed to block each stage of the exploit chain and provide interim protection while organizations apply official updates.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.