This article is produced with scandiweb's eCommerce expertise

Collaborate with our development, PPC, SEO, data & analytics, or customer experience teams to grow your eCommerce business.

StyleSmuggler Patch: Which Magento Versions Adobe Covers and How to Apply It

On September 7, 2026, Adobe released an official fix for the StyleSmuggler vulnerability (CVE-2026-75650) in Security Bulletin APSB26-146. If you run a store on Magento or Adobe Commerce, this is the update you’ve been waiting for since this became public, and it should be a priority.

Update (September 18, 2026): Adobe has expanded the hotfix. Magento Open Source 2.4.4 and 2.4.5 now have an official patch, and Adobe offers separate packages for specific patch releases. Before you download anything, match your exact version against Adobe’s table, including the -p number.

Adobe’s hotfix now covers Adobe Commerce and Magento Open Source from 2.4.4 up. The first release left out Open Source 2.4.4 and 2.4.5, and Adobe has since added packages for them. For anything older, we rebuilt Adobe’s fix ourselves for 41 versions, Magento 2.2.0 through 2.4.3-p3.

Here’s what Adobe released, who’s covered, and what to do this week depending on the version you’re on.

Key takeaways

  • StyleSmuggler is CVE-2026-75650, a CVSS 10.0 unauthenticated remote code execution flaw, exploited since September 4, 2026.
  • Adobe’s fix arrived on September 7 in Security Bulletin APSB26-146, as the VULN-39341 hotfix.
  • It covers Adobe Commerce 2.4.4 to 2.4.9, Adobe Commerce B2B 1.3.3 to 1.5.3, and Magento Open Source 2.4.4 to 2.4.9.
  • Patching is not enough on its own. Adobe requires rotating the encryption key and every credential it protects.
  • We rebuilt Adobe’s fix for 41 unsupported versions, Magento 2.2.0 through 2.4.3-p3.

A quick recap of what StyleSmuggler is

StyleSmuggler is a critical vulnerability in the Magento and Adobe Commerce core, disclosed by security firm Sansec on September 5. It lets an unauthenticated attacker, with no login and no user interaction, run code on a store’s server, reach its data, and plant a persistent backdoor.

It affects every current version, and being fully patched beforehand was no protection: the attack was reproduced on clean 2.4.7, 2.4.8, and 2.4.9 installs, and the first confirmed case was on 2.4.6 with Adobe’s July and August updates already in place.

What Adobe released

Adobe has released an official fix for the StyleSmuggler vulnerability (CVE-2026-75650) in Security Bulletin APSB26-146.

For Adobe Commerce (including B2B and Cloud), the hotfix covers 2.4.4 through 2.4.9. If you’re on a supported Adobe Commerce version, there is a patch for you.

For Magento Open Source, the hotfix covers 2.4.6 through 2.4.9 only. There is no official fix for Magento Open Source below 2.4.6.

Does Adobe’s hotfix cover your version?

VersionAffectedOfficial fix from Adobe
Adobe Commerce 2.4.4–2.4.9YesYes – VULN-39341
Adobe Commerce B2B 1.3.3–1.5.3YesYes – VULN-39341
Magento Open Source 2.4.6–2.4.9YesYes – VULN-39341
Magento Open Source 2.4.4–2.4.5YesYes (since Sep 18) – VULN-39341
Magento Open Source 2.2.0–2.4.3-p3YesNone
Adobe Commerce below 2.4.4YesNone
Affected ranges per Sansec. Hotfix coverage per Adobe Security Bulletin APSB26-146.

🚀 Quick takeaway

Adobe’s hotfix now starts at 2.4.4 on both Adobe Commerce and Magento Open Source. Below that there is no official fix, and our backport covers 2.2.0 through 2.4.3-p3.

If you run Magento Open Source 2.4.4 or 2.4.5, Adobe now has a patch for you. The right package depends on your exact patch release, so check the -p number before you download.

If your version has an official fix, apply Adobe’s VULN-39341 hotfix now, then rotate your credentials (see below).

On an older version Adobe left out?

If your version shows no official fix, Adobe Commerce below 2.4.4 or Magento Open Source 2.4.3-p3 and earlier, none is coming. We rebuilt Adobe’s fix for every Magento version from 2.2.0 to 2.4.3-p3, 41 versions in total, so those stores aren’t left exposed.

Get the patch for your version here: StyleSmuggler fix for older Magento versions (2.2.0 to 2.4.3).

Before you patch: check for a break-in

If your store has been online since September 4, look before you patch. A patch closes the hole, but it does not remove an attacker who is already inside. Known indicators of compromise:

  • Unexpected “Payment Transaction Failed Reminder” emails
  • Unfamiliar background processes on the server
  • New scheduled tasks
  • Unknown files in the report and temp folders

If you find any of these, prioritize a full compromise investigation alongside patching.

🚀 Quick takeaway

Check before you patch. The hotfix closes the entry point but does not remove a backdoor already installed. Any store online since September 4 needs a compromise check too.

How to apply the Adobe patch

  1. Start on staging. Take a snapshot you can roll back to.
    • Put the store into maintenance mode before you begin: bin/magento maintenance:enable
    • Disable cron, so no scheduled job runs against a half-rotated set of credentials.
  2. Apply the package for your exact build. Download it from Adobe’s APSB26-146 knowledge base article. Adobe now has several packages, and a 2.4.8-p2 store needs a different one than a 2.4.8-p1 store.
  3. Test the shopping journey. Cart, checkout, payment, and transactional email. Then repeat on production.
  4. Rotate the encryption key and all credentials.
    • Flush the cache once rotation is complete: bin/magento cache:flush
    • Re-enable cron, then take the store out of maintenance mode: bin/magento maintenance:disable

This is the short path. Adobe’s APSB26-146 article has the full 15-step sequence. It includes rotating Fastly credentials through a support ticket and, on Adobe Commerce Cloud, a redeploy so new database credentials take effect.

On Adobe Commerce Cloud, you can confirm the hotfix is installed with the Quality Patches Tool: vendor/bin/magento-patches -n status | grep "39341|Status". An “Applied” status tells you the patch is in place. It tells you nothing about whether someone got in before you applied it.

Patching is only half; you must rotate credentials

Adobe is explicit that applying VULN-39341 is not enough on its own. Because the vulnerability could expose your store’s encryption key, and that key protects integration tokens, payment gateway credentials, and system automation tokens, you must rotate the encryption key and every credential it protects.

In practice, after applying the hotfix, that means rotating:

  • Admin panel user passwords
  • REST, SOAP, and GraphQL integration tokens (deactivate and regenerate)
  • OAuth client secrets for connected apps
  • Payment gateway API credentials, at the provider (Stripe, Braintree, Adyen, PayPal, and so on)
  • Database credentials
  • Fastly credentials (via an Adobe support ticket)
  • SSH and deploy keys, and any cron or system service-account credentials
  • API keys for shipping, tax, and other third-party extensions.

🚀 Quick takeaway

Rotating the encryption key alone leaves you exposed. Credentials captured before rotation stay usable until they are regenerated at their source, so rotate every token and key where it was issued, not only inside Magento.

Frequently asked questions

Which Magento versions does Adobe’s StyleSmuggler patch cover?

Adobe’s VULN-39341 hotfix, released in Security Bulletin APSB26-146, covers Adobe Commerce 2.4.4 to 2.4.9, Adobe Commerce B2B 1.3.3 to 1.5.3, and Magento Open Source 2.4.4 to 2.4.9.

Is there a StyleSmuggler patch for Magento Open Source 2.4.4 and 2.4.5?

Yes. Adobe’s first release covered Magento Open Source from 2.4.6 only, and Adobe has since added packages for 2.4.4 and 2.4.5. For 2.4.3-p3 and older there is still no Adobe fix. scandiweb rebuilt it for 41 versions, Magento 2.2.0 through 2.4.3-p3.

Does applying the StyleSmuggler patch mean my store is safe?

No. The patch closes the vulnerability but does not remove an attacker who is already inside. Adobe requires rotating the encryption key and every credential it protects, at the source. Stores that were online on or after September 4, 2026 should also be checked for signs of compromise.

What is CVE-2026-75650?

CVE-2026-75650 is the identifier for StyleSmuggler, a critical unauthenticated remote code execution vulnerability in Magento Open Source and Adobe Commerce, scored CVSS 10.0. Sansec disclosed it on September 5, 2026, after attacks began on September 4. Adobe published the fix on September 7 in APSB26-146.

How do I check which Magento version I am running?

Run bin/magento --version from your Magento root, or read the version in the Admin dashboard footer. On Adobe Commerce Cloud, check the magento/product-enterprise-edition constraint in composer.json. Match that version against the coverage table above before applying any patch.

Should I still check for a compromise if I patched immediately?

Yes, if the store was online on or after September 4, 2026. Exploitation began a day before public disclosure, so a store could have been reached before anyone knew the vulnerability existed. Patching closes the entry point but leaves any backdoor already installed in place.

Rather have scandiweb do it for you?

We check your store for a break-in, apply the patch, test the shopping journey, and rotate the keys. For the full account of how we protected client stores in the days before Adobe’s fix existed, see Magento and Adobe Commerce Under Attack: scandiweb’s Rapid Response to StyleSmuggler.

Not a scandiweb client yet? Start with a free security check that needs no access to your store, or talk to our Magento team.

If you enjoyed this post, you may also like