CVE-2026-75650 is a critical vulnerability in Adobe Commerce, also referred to as StyleSmuggler, caused by improper neutralization of special elements used in a template engine. The vulnerability has a CVSS score of 10.0 and can allow unauthenticated attackers to achieve arbitrary code execution. Exploitation does not require user interaction or prior authentication, making the vulnerability particularly severe. Attackers can abuse the template processing mechanism to inject malicious code and execute it within the affected application. The vulnerability impacts confidentiality, integrity, and availability of affected systems. Adobe has confirmed that CVE-2026-75650 is being exploited in the wild. The flaw affects Adobe Commerce and Magento Open Source from 2.4.4 through 2.4.9. Adobe Commerce B2B versions 1.3.3 through 1.5.3 are also affected. Older builds in those branches are vulnerable too.
We recommend you to refer below link: https://helpx.adobe.com/security/products/magento/apsb26-146.html[/subscribe_to_unlock_form]
CVE-2026-75650 is a critical vulnerability in Adobe Commerce, also referred to as StyleSmuggler, caused by improper neutralization of special elements used in a template engine. The vulnerability has a CVSS score of 10.0 and can allow unauthenticated attackers to achieve arbitrary code execution. Exploitation does not require user interaction or prior authentication, making the vulnerability particularly severe. Attackers can abuse the template processing mechanism to inject malicious code and execute it within the affected application. The vulnerability impacts confidentiality, integrity, and availability of affected systems. Adobe has confirmed that CVE-2026-75650 is being exploited in the wild. The flaw affects Adobe Commerce and Magento Open Source from 2.4.4 through 2.4.9. Adobe Commerce B2B versions 1.3.3 through 1.5.3 are also affected. Older builds in those branches are vulnerable too.
We recommend you to refer below link: https://helpx.adobe.com/security/products/magento/apsb26-146.html[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]