惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
V
Visual Studio Blog
IT之家
IT之家
博客园 - 【当耐特】
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
B
Blog
爱范儿
爱范儿
阮一峰的网络日志
阮一峰的网络日志
云风的 BLOG
云风的 BLOG
Vercel News
Vercel News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
H
Help Net Security
J
Java Code Geeks
aimingoo的专栏
aimingoo的专栏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog RSS Feed
Blog — PlanetScale
Blog — PlanetScale
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research

Blog

SSL Integration Center: BYO CA & DigiCert TLM | Imperva OWASP LLM Top 10: What Comes Next for AI Security | Imperva Imperva API Security Token & Authentication Risk Report: Nearly 40% of APIs Face Multiple Authentication Risks | Imperva Imperva API Security Token & Authentication Risk Report: Nearly 40% of APIs Face Multiple Authentication Risks | Imperva www.imperva.com Imperva Customers Protected Against XSS2Shell (CVE-2026-64638) in WordPress Core | Imperva What SecureIQLab Cloud WAAP 5.0 means for your application security | Imperva Generative AI Security: Why AI Needs New Defenses | Imperva ShadowAI-Watch: Bringing AI Agent Activity Out of the Shadows | Imperva Imperva Customers Protected Against Novel HTTP Desync Attacks | Imperva Agentic AI Security: The Chatbot Era Is Over | Imperva MCP Server Security: Risks, Attacks & Controls | Imperva Google Australia Customers Now Benefit From Imperva Cloud-Native WAAP Security | Imperva Closing the Sovereignty Gap: Bringing Active API Protection to Self-Managed Environments | Imperva Imperva Customers Protected Against CVE-2026-16723: Critical FastJson 1.x Zero-Day RCE | Imperva Imperva Customers Protected Against "wp2shell" Pre-Authentication RCE in WordPress Core | Imperva Code Injection in Perforce Helix Core (CVE-2026-6902) | Imperva AI Bot Traffic: Which Bots to Allow or Block | Imperva API Security Tools: What Each One Protects | Imperva CVE-2025-54068 Laravel Livewire Credential Theft Campaign: 6,000+ Applications Compromised | Imperva On-Premises API Security on Kubernetes | Imperva AI Security Assistant for Faster Investigations | Imperva Best WAAP Solutions 2026: Enterprise Buyer Guide | Imperva Compromise OpenClaw with Prompt Injections in Message Objects The Clock Is Already Ticking: Why Post-Quantum Cryptography Can’t Wait Imperva Customers Protected Against CVE-2026-49975 (HTTP/2 Bomb) DoS Imperva Customers Protected Against CVE-2026-45247 in Mirasvit Full Page Cache Warmer for Magento Real-Time Webhook Notifications: No More Lost Security Alerts Imperva Customers Protected Against CVE-2026-9082 in Drupal Core Dify: When Your AI Platform Becomes the Attack Surface
Imperva Customers Protected Against StyleSmuggler (CVE-20...
Gabi Sharadin · 2026-09-11 · via Blog

Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source

TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and achieve remote code execution. Adobe assigned the vulnerability a CVSS score of 10.0 and released an emergency hotfix after exploitation was observed in the wild. Imperva Cloud WAF and On-Prem WAF customers are protected against exploitation attempts associated with CVE-2026-75650. 

Understanding the StyleSmuggler Vulnerability 

StyleSmuggler is an improper neutralization vulnerability in Magento’s template engine. Attackers can abuse the processing of styles properties to smuggle malicious PHP code past existing safeguards and into content that Magento later renders. 

The attack occurs in two stages. First, the attacker sends a crafted request that causes malicious PHP code to be stored within Magento-generated content, such as a failure report. The attacker then triggers application functionality that renders the poisoned content, including Magento’s standard failed-payment email process. When the template is rendered, the injected PHP executes on the server. 

No authentication or user interaction is required. The recipient does not need to open the failed-payment email, and the attack can succeed even if the email is never delivered. Successful exploitation gives the attacker arbitrary code execution in the context of the Magento application, potentially enabling malware deployment, persistent access, credential theft, payment-data compromise, or further movement within the environment. The vulnerability affects supported versions across multiple Adobe Commerce and Magento Open Source branches, including systems that had received recent security patches. 

Observed post-exploitation activity has included the deployment of persistent Linux backdoors disguised as legitimate processes such as kworker, fc-cache, and chronyd. Researchers have also identified a separate campaign using the vulnerability to install a PHP web shell, demonstrating that multiple threat actors are already attempting to operationalize StyleSmuggler. 

What Imperva Has Seen So Far 

Imperva has observed exploitation activity targeting websites across 15 countries, indicating that StyleSmuggler scanning and attack attempts are already geographically widespread. The United States accounts for 25% of targeted sites, followed by Mexico at 15.9%, Spain at 14%, and Singapore at 13.6%. 

Screenshot 2026 09 10 at 10.40.57 AM

Retail websites represent the largest share of observed targets at 39.5%, consistent with Magento’s extensive use across ecommerce environments. Lifestyle sites account for another 19.5% of targets, followed by healthcare at 17.9%. 

Screenshot 2026 09 10 at 10.41.25 AM

Attack traffic has primarily automated attacks. While client identifiers can be modified or spoofed, their prevalence is consistent with attackers using scripted tools to automate scanning and exploitation rather than interacting through conventional web browsers. 

Imperva protections are actively identifying and blocking malicious requests associated with the StyleSmuggler attack chain before they can reach protected applications. 

Conclusion 

CVE-2026-75650 poses an immediate risk: it enables unauthenticated remote code execution, has already been weaponized, and can give attackers direct control over ecommerce servers. Adobe Commerce and Magento Open Source administrators should apply the VULN-39341 hotfix immediately and investigate potentially exposed systems for signs of compromise. As exploitation began before a patch was available, applying the hotfix does not remove malware or persistence mechanisms that may already be present. 

Imperva Cloud WAF and On-Prem WAF customers are protected against exploitation attempts associated with StyleSmuggler. Imperva will continue monitoring the campaign as attackers refine their payloads and additional activity emerges. 

Try Imperva for Free

Protect your business for 30 days on Imperva.

Start Now