Security alert: Update Magento and Adobe Commerce ASAP

An urgent hotfix is available to patch a critical zero-day vulnerability in Magento and Adobe Commerce. Update your software as soon as you can.

/
Date

Simple icons for a padlock, alert symbol and a shield sit in front of a grey/bue background. The SiteHost logo sits in front of the shield.

A critical vulnerability in Adobe Commerce and Magento was already being exploited before a hotfix became available. If you haven't already acted against CVE-2026-75650, known as "StyleSmuggler", it is crucial that you do.

StyleSmuggler is an unauthenticated remote code execution flaw which gives attackers deep access to your store and customers' data. According to CrowdSec (with emphasis added):

Code execution on a Magento server means the attacker sits where card data is entered, customer records are stored, and the database password lives. Sansec found a Rust backdoor disguised as system processes that beacons to its operators over traffic shaped like time-sync (NTP) packets, and a second actor dropping a PHP web shell into the product image cache. That is the setup for card skimming and for reselling access to the store. CrowdSec CTI classifies 98% of the observed intent as infrastructure takeover.

Affected versions

Essentially every currently-supported version of Magento or Adobe Commerce is affected.

  • Magento Open Source 2.4.6 to 2.4.9.

  • Adobe Commerce 2.4.4 to 2.4.9.

  • Adobe Commerce B2B 1.3.3 to 1.5.3.

If you are running anything older, it is already out of support and you should expect it to also be affected. The safest course of action is to update to a supported version before applying the hotfix.

To start taking action, see Adobe's security bulletin, including the hotfix.

Even if your server is managed, this is an application update for you to make

Whether your server is managed or unmanaged, this is an update that you need to make. Managed Services cover the entire infrastructure layer (like patching Linux vulnerabilities in their hundreds), but not the application layer.

Please apply the hotfix to Magento or Adobe Commerce as soon as you possibly can.

Prices in NZD, excluding GST