Commerce Platforms & DTC
Magento

When the Payment-Failure Email Is the Exploit: Inside the Magento Template Rendering Chain of CVE-2026-75650

How CVE-2026-75650 turns Magento's own payment-failure email rendering into unauthenticated RCE, and what to do after patching. Tagged with magento, rce, templateinjection, incidentresponse.
dev.to
September 18, 2026
7
When the Payment-Failure Email Is the Exploit: Inside the Magento Template Rendering Chain of CVE-2026-75650
WHAT HAPPENED
When the Payment-Failure Email Is the Exploit: Inside the Magento Template Rendering Chain of CVE-2026-75650 Opening CVE-2026-75650 is an unauthenticated remote code execution vulnerability in Adobe Commerce and Magento Open Source that reached the CISA Known Exploited Vulnerabilities catalog on 8 September 2026. Dutch ecommerce security firm Sansec, which named the campaign StyleSmuggler, documented exploitation starting 4 September 2026. Adobe published the emergency hotfix VULN-39341 on 7 September 2026 under advisory APSB26-146. A store that was compromised before the hotfix did not become safe by applying it. Technical context The flaw is classified as CWE-1336, improper neutralization of special elements used in a template engine.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY