Your Latest Magento Patch Wasn't the Problem
A zero-day the researchers at Sansec are calling StyleSmuggler (CVE-2026-75650, rated CVSS 10.0) has been quietly installing backdoors in Magento Open Source and Adobe Commerce since September 4, and the detail that should make any store operator pause is not the one in the headline. The first recorded compromise landed on a target running the newest security updates. Every version from 2.4.4 up to and including 2.4.9 is affected, and no login is required to get in. The bug slips malicious PHP into Magento's template system through the styles properties, riding past the existing safeguards, and then gets triggered by something totally mundane: a fake "failed payment" email. Unauthenticated remote code execution on a platform installed on more than 160,000 sites, about 14,000 of them in the top million. Adobe dropped an emergency hotfix on September 7 under APSB26-146, but "patched" is doing a lot of heavy lifting in a sentence like that, and this is why. Becaus...