TTO-2026-0908-109 · September 8, 2026 PatchFollow-Up

Adobe Patches StyleSmuggler — CVE-2026-75650 CVSS 10.0 Assigned Four Days After Active Exploitation Began

adobe.comCVE-2026-75650 CVSS 10.0APSB26-146Hotfix VULN-39341Follow-up to TTO-2026-0907-104

Summary

Adobe has shipped an emergency patch for the StyleSmuggler zero-day affecting Magento Open Source and Adobe Commerce, four days after active exploitation was first confirmed. The vulnerability has been assigned CVE-2026-75650 with a CVSS score of 10.0 and is addressed in Adobe security bulletin APSB26-146 via hotfix VULN-39341. This bulletin updates TTO-2026-0907-104, which was published on September 7 when no patch, CVE, or advisory existed.

Timeline

DateEvent
Sep 4, 2026First confirmed exploitation — victim running fully patched Magento 2.4.6-p15
Sep 5, 2026Sansec publishes StyleSmuggler advisory; no CVE, no patch
Sep 7, 2026Adobe confirms it is working on a fix; TTO-2026-0907-104 published
Sep 7-8, 2026Adobe publishes APSB26-146, assigns CVE-2026-75650 CVSS 10.0, releases hotfix VULN-39341

What Changed

Adobe bulletin APSB26-146 formally assigns CVE-2026-75650 and rates it Critical at CVSS 10.0 — the maximum possible score. Hotfix VULN-39341 is classified as Priority 1, Adobe's highest patch priority, reserved for vulnerabilities being actively exploited. Adobe confirms in-the-wild exploitation in the bulletin itself.

Operators running Adobe Commerce or Magento Open Source should apply VULN-39341 immediately. Adobe also advises rotating the Commerce encryption key and any credentials it may have protected. Unexplained Payment Transaction Failed Reminder emails, unexpected cron entries, or processes named kworker or fc-cache on store servers remain indicators of prior compromise regardless of patching.

Domain Intelligence

adobe.com — 62.06

Score unchanged from TTO-2026-0907-104. Adobe is the vendor that both introduced the vulnerability and shipped the patch. The score reflects adobe.com's broader domain trust posture and is not a measure of the patched vulnerability's severity, which at CVSS 10.0 is the maximum possible.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026