What happened
Adobe published APSB26-146 on 7 September 2026 and said CVE-2026-75650 is being exploited in the wild. Adobe describes an unauthenticated template-engine weakness permitting arbitrary code execution and assigns a priority-one rating. The hotfix is VULN-39341, delivered as VULN-39341-composer-patches.zip rather than a full product release. Adobe rates the unauthenticated template-engine flaw CVSS 10.0 and lists affected Adobe Commerce 2.4.4 through 2.4.9 branches, Magento Open Source 2.4.4 through 2.4.9 branches and Adobe Commerce B2B 1.3.3 through 1.5.3 branches. Adobe’s published Commerce Cloud verification command is vendor/bin/magento-patches -n status | grep “39341|Status”, and the expected result is Applied.
Sansec places first confirmed StyleSmuggler exploitation at 22:20 UTC on 4 September 2026, before an Adobe hotfix existed. Its analysis says the attack poisons data processed by Magento’s template system and triggers execution while a failed-payment email is rendered. Successful attacks launched a Rust backdoor disguised through process names including kworker, fc-cache and chronyd. On 7 September 2026 at 09:50 UTC, Sansec says an implant on an already affected host re-dropped itself as chronyd. The newest described variant used /tmp/.chrony-<8hex>/chronyd, reported implant version 2.1.5 and could relaunch without a visible cron entry. Sansec published 99.84.67.186:443 and 185.157.160.251:123 alongside SHA-256 values e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 and b79dfdc1eed860e0b76c629d6adfce251db379b0b45a6d728d4ef483f7551420.
Adobe requires rotation of the encryption key and potentially exposed administrator, integration, OAuth, payment, database, SSH, deployment and extension credentials at their originating systems. Adobe warns that rotating the Commerce encryption key alone does not invalidate credentials an attacker may already have obtained. Attribution posture: Adobe and Sansec confirm exploitation, but neither source names or attributes a threat actor.
Why this matters now
The emergency patch changes the remediation decision, but it does not erase the period of exposure. Sansec says stores were exploited for three days before Adobe released the hotfix, including a victim that reported a clean security:patch-status result. Executives should therefore reject any closure statement based solely on version currency or successful patch installation. The required work is now a coordinated vulnerability, incident-response and credential-containment programme covering the application, Linux host, payment integrations and every secret protected by the Commerce encryption key.
The placement is unusually consequential. Adobe Commerce commonly sits on an internet-facing revenue path and holds privileged connections to payment processors, tax and shipping services, databases, deployment systems and customer accounts. Adobe explicitly requires rotation at the credential source because changing the Commerce encryption key does not invalidate secrets already read by an intruder. Maintenance windows, revenue availability and third-party coordination may conflict, but delaying the hotfix or secret rotation preserves a known path into a commercially critical control point.
The decision for security leaders
Declare a coordinated emergency change covering patching, compromise assessment and secret rotation. Application ownership alone cannot close this exposure because the affected platform bridges Linux hosts, payment providers, databases, deployment systems and customer identity. Name one incident-capable executive owner who can resolve conflicts between evidence preservation, maintenance downtime and revenue availability.
Separate containment from eradication. A successful hotfix result proves only that the vulnerable path was changed. Require retrospective log review, process and filesystem inspection, network-indicator searches and validation of media directories before permitting a clean disposition. Rebuild affected nodes from trusted sources when any implant, web shell, unexplained task or unauthorised credential use is found.
Evidence of closure
- Hotfix-status output shows VULN-39341 as Applied on every in-scope instance.
- Endpoint and filesystem hunts return no StyleSmuggler process, path, hash or network matches.
- Credential records show every Adobe-listed secret replaced at its originating system.
- Rebuilt nodes pass transaction, integration and payment validation after key rotation.
The Security.io assessment
The material change is Adobe’s emergency hotfix and explicit exploitation confirmation, combined with Sansec’s same-day evidence that the implant continued changing names, persistence and command-and-control behaviour. That combination raises confidence in the remediation path while reducing confidence in narrow indicator-only hunts. Organisations should use the published indicators as starting points, not as the definition of compromise.
Patch verification, malware hunting and credential containment must produce separate evidence. A clean application scan cannot prove the Linux host is clean; an absent cron entry cannot exclude the chronyd variant; and a rotated Commerce encryption key cannot revoke secrets already copied into attacker infrastructure. Closure requires a joined evidence pack that covers every instance, host, integration and credential path.
Questions for the morning meeting
- Can the organisation identify every Adobe Commerce and Magento instance, including managed, development and recovery environments?
- Who owns coordinated rotation of payment, integration, database, deployment and administrator credentials?
- Which evidence distinguishes a patched store from a store proven uncompromised?
- Can affected nodes be rebuilt without losing transaction, order or forensic evidence?