Categories
Magento

Urgent Magento Security Update – StyleSmuggler / CVE-2026-75650

A critical new vulnerability affecting Magento Open Source and Adobe Commerce is being actively exploited.

The vulnerability, known as StyleSmuggler and tracked as CVE-2026-75650, could allow an unauthenticated attacker to execute arbitrary code on a vulnerable Magento installation.

Adobe has given the vulnerability the maximum CVSS severity score of 10.0 (Critical).

What DX3 Has Done

As soon as details of the active attacks became available, DX3 began deploying server-level protection across our Magento hosting infrastructure, rather than waiting for the official Adobe patch.

Standard Magento Stores

For Magento installations that do not require public GraphQL access, we have blocked the Magento GraphQL endpoint at the origin web server.

This prevents the vulnerable endpoint from being publicly accessible.

Hyvä Magento Stores

Hyvä-based Magento stores can legitimately require GraphQL functionality, so simply disabling GraphQL could cause problems with the storefront or checkout.

For identified Hyvä installations, we have therefore implemented targeted server-level filtering designed to block the observed StyleSmuggler attack requests while allowing legitimate Magento GraphQL traffic to continue.

We have tested this protection against both normal and URL-encoded variants of the observed attack pattern while confirming that legitimate GraphQL requests continue to function.

Protection Does Not Depend on Cloudflare

Importantly, the DX3 mitigation has been implemented at the origin server level.

This means the protection does not depend on a Magento store using Cloudflare and cannot simply be bypassed by sending traffic directly to the origin server.

Where appropriate, protection has also been implemented at multiple layers of the web stack to prevent malicious requests from reaching Magento.

Adobe Has Now Released the Official Fix

Adobe released security bulletin APSB26-146 on 7 September 2026 addressing CVE-2026-75650.

Adobe confirms that the vulnerability is being actively exploited in the wild.

The official Adobe security update should therefore be treated as a priority for affected Magento Open Source and Adobe Commerce installations.

What Magento Store Owners Need to Do

Apply Adobe’s official CVE-2026-75650 hotfix as soon as possible.

The server-level protections deployed by DX3 provide an important emergency defence, but they should not be considered a permanent replacement for correcting the underlying Magento vulnerability.

If your Magento website is maintained by a development agency, we recommend asking them to review Adobe security bulletin APSB26-146 and arrange installation and testing of the appropriate hotfix as a priority.

Patching Is Not the Same as Checking for Compromise

There is another important consideration.

The vulnerability was being exploited before the official Adobe patch became available.

Installing the security patch prevents the vulnerability from being exploited in future, but it does not establish whether a Magento installation was attacked before it was patched or protected.

Magento installations should therefore also be checked for indicators of compromise and unexpected modifications.

DX3 is continuing to monitor the situation and the available technical indicators as further information becomes available.

DX3 Magento Customers

For Magento websites hosted by DX3, we have already deployed server-level mitigation across our Magento infrastructure where applicable.

Our recommendation now is:

  1. Keep the DX3 server-level protection in place.
  2. Apply Adobe’s official CVE-2026-75650 hotfix.
  3. Check the Magento installation for evidence of previous compromise.
  4. Test the website, checkout and integrations following patching.
  5. Only reconsider the temporary server-level restrictions once the official patch has been successfully deployed and verified.

If your Magento development is handled by a third-party agency, please forward this information to them and ask them to arrange the Adobe security update.

Further Information

Adobe Security Bulletin: APSB26-146 – CVE-2026-75650

Vulnerability: StyleSmuggler

Severity: Critical – CVSS 10.0

Affected platforms: Adobe Commerce and Magento Open Source

Current status: Actively exploited

DX3 will continue to monitor developments and maintain additional server-level protection while customers and development agencies roll out the official security update.