WHAT HAPPENED
StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento A storefront can pass every routine security check and still be running an exploitable template engine. That is the situation Adobe Commerce and Magento Open Source merchants faced in September 2026, when attackers turned an ordinary transactional email into an unauthenticated remote code execution path. The vulnerability is CVE-2026-75650, named StyleSmuggler by the Dutch ecommerce security firm Sansec. The classification is CWE-1336, improper neutralization of special elements used in a template engine. An attacker first plants crafted PHP code inside data that Magento itself generates, such as a payment failure report.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY
