Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

“StyleSmuggler” – Adobe Commerce, Adobe Commerce B2B, and Magento RCE (CVE-2026-75650): Overview and Takeaways

Summary

CVE-2026-75650 (CVSS 10.0) lets unauthenticated attackers inject PHP through Magento's email template engine for RCE, with in-the-wild exploitation and Rust backdoors confirmed before the hotfix.
CVE
CVE-2026-75650
Published
Collected

original ↗