Commerce Platforms & DTC
Magento

StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento

CVE-2026-75650 let attackers turn a Magento payment failure email into unauthenticated RCE and install a Rust backdoor that hides as a kernel thread. Tagged with cybersecurity, ecommercesecurity, vulnerabilitymanagement.
dev.to
September 19, 2026
7
StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento
WHAT HAPPENED
StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento A storefront can pass every routine security check and still be running an exploitable template engine. That is the situation Adobe Commerce and Magento Open Source merchants faced in September 2026, when attackers turned an ordinary transactional email into an unauthenticated remote code execution path. The vulnerability is CVE-2026-75650, named StyleSmuggler by the Dutch ecommerce security firm Sansec. The classification is CWE-1336, improper neutralization of special elements used in a template engine. An attacker first plants crafted PHP code inside data that Magento itself generates, such as a payment failure report.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY