Key points
- A critical vulnerability tracked as CVE-2026-75650, rated 10.0 on the CVSS scale, allows unauthenticated remote code execution on Adobe Commerce and Magento Open Source.
- Sansec, which discovered and named the bug StyleSmuggler, said exploitation began on September 4, giving attackers around three days before Adobe shipped a hotfix.
- ASD's ACSC is aware of a substantial number of potentially vulnerable instances in Australia and advises organisations to patch as soon as possible.
The Australian Signals Directorate has sent out a critical alert about a vulnerability in the Adobe Commerce and Magento Open Source ecommerce platforms that many stores in the country run for their online businesses.
Tracked as CVE-2026-75650 and rated 10.0 on the CVSS scale, the vulnerability is an improper neutralisation of special elements used in a template engine, leading to unauthenticated remote code execution.
ASD's Australian Cyber Security Centre (ACSC) said in its alert.that exploitation requires the /graphql endpoint to be exposed.
The attack chain never touches an obvious injection point, instead manipulating "styles" properties in a GraphQL request to slip PHP code past input sanitisation and into a file the platform writes during normal operation, such as a payment failure report.
It is not clear how many stores in Australia are at risk, or have already been attacked, but ACSC said it is aware of "a substantial number of potentially vulnerable instances" locally.
Dutch ecommerce security firm Sansec discovered the bug, named it StyleSmuggler, and said exploitation began on September 4, with the first confirmed compromise at 22:20 UTC.
It published on September 5 before completing its analysis, at a point when Adobe had issued neither a CVE identifier nor an advisory.
"Sansec is publishing early because stores are being compromised right now," the company said.
Attackers had around three days to break into stores before Adobe shipped a hotfix for the vulnerability.
ASD advises organisations to review their networks and environments for vulnerable versions of the ecommerce platforms, review mitigation advice, and to apply patches as soon as possible.
Users who have Adobe Commerce and Magento managed by third parties such as an MSP or enterprise IT provider should contact them to ensure the software has been patched, and monitor for suspicious activity.
Adobe's guidance advises merchants to rotate the Magento encryption key and the credentials it protected.
It also warned that patching stores during the three-day window of opportunity before the hotfix became available would not remove implants placed by attackers on systems.
The United States Cybersecurity and Infrastructure Security Agency (CISA) has added the bugs to its Known Exploited Vulnerabilities (KEV) catalogue.
In just over two years, the ecommerce platform has suffered three serious flaws that don't require authentication to exploit: CosmicSting (CVE-2024-34102), which Sansec linked to 4275 confirmed store breaches, and SessionReaper (CVE-2025-54236), which saw mass exploitation last October when 62 percent of stores were still unpatched six weeks after the fix shipped.

iTnews State of Security Breakfast Melbourne
NiCE World APAC 2026
Sydney Cloud & Datacenter Convention 2026
iTnews Executive Retreat - Security Leaders Edition
Can Testing Keep Up? Quality in the Age of Accelerating Delivery



