scandiweb
Security alert · StyleSmuggler · Updated September 24, 2026

A critical Magento vulnerability.Our team is on it.

A new Magento flaw, StyleSmuggler, is being exploited. scandiweb is installing Adobe’s fix and has rebuilt it for the versions Adobe left out.

Patch statusAdobe released an emergency hotfix on September 7 (APSB26-146, CVE-2026-75650). It covers Magento Open Source 2.4.6 to 2.4.9 and Adobe Commerce 2.4.4 to 2.4.9. Magento Open Source stores on 2.4.5 or older get no patch.

What this means for your store

Every version from 2.4.4 to 2.4.9 is affected. That is well over 100,000 stores worldwide.

Recent updates may not protect you

The attack has affected a store with Adobe’s July and August security updates installed. Only the September 7 hotfix closes the hole, and installing it does not undo a break-in that happened before.

Attackers do not need a login

The vulnerability allows attackers to run malicious code without a customer or administrator account.

Your store and its data could be at risk

A successful attack could allow someone to access sensitive data, modify your store, or install malware.

Protection and investigation both matter

The hotfix blocks new attacks. Your team also needs to check whether attackers gained access before it was installed, and to rotate the encryption key and credentials, as Adobe requires.

Older versions get no patch

Adobe’s hotfix covers Magento Open Source 2.4.6 to 2.4.9 and Adobe Commerce 2.4.4 to 2.4.9. Magento Open Source stores on 2.4.5 or older get no fix, and the only way to close the hole for good is to upgrade. For 2.2.0 to 2.4.3, scandiweb has rebuilt the hotfix in the meantime.

Download the patch for 2.2.0 to 2.4.3

This alert does not mean your store has been compromised. It means you should check your exposure and take protective action now.

Get a free security consultation

How we’re protecting your store

  1. 1

    Check for signs of compromise

    We inspect your store for malicious files and suspicious activity. If we find anything, you hear about it first.

  2. 2

    Install the fix

    We install Adobe’s September 7 hotfix and rotate the encryption key and credentials. Versions Adobe no longer patches get an upgrade plan.

  3. 3

    Test the shopping journey

    Cart and checkout by hand, then our automated tests.

Running 2.2.0 to 2.4.3?

Download the patch Adobe didn’t ship

Adobe’s hotfix stops at Commerce 2.4.4 and Open Source 2.4.6. scandiweb rebuilt it for 41 older versions, and the security advisory now points to it. Leave your email and we send you the patch bundle with a short guide.

  • 41 patch files, one per Magento version from 2.2.0 to 2.4.3-p3
  • Which versions Adobe’s hotfix covers, and which get nothing
  • What to check for before you patch, and how to apply it in 4 steps

Apply the patch on staging first, and check the store for a break-in if it has been online since September 4.

Client replies

What clients said

Every scandiweb Magento and Adobe Commerce client heard from us on the day the flaw became public.

“Thank you for the proactive response. Please proceed with the assessment and any required mitigation activities as outlined in your email.”
Purdys Chocolatier
“Thanks, I appreciate the proactive approach here. Please keep us updated.”
Airthings
“Thank you very much for your support on this.”
Beauty Works
“Thanks all. We greatly appreciate the proactive response.”
Purdys Chocolatier

Get a free security consultation

Share your store address and answer a few questions. It helps our Magento engineers understand your setup and prepare for the call.

Step 1 of 3 · Your store

Rather talk first? Book a call with our Magento security team

Questions

Common questions

Does StyleSmuggler affect Adobe Commerce, or only Magento Open Source?

Both. Adobe Commerce and Magento Open Source share the same core code, and the flaw is in that core. Stores on Adobe Commerce Cloud are affected too.

Which versions are affected?

Every version from 2.4.4 up to 2.4.9, including the latest patch levels, and older versions are affected too. The first confirmed victim ran 2.4.6 with the latest security patches installed.

My store has all the latest security patches. Am I safe?

Not unless the September 7 hotfix is installed. The first confirmed victim had Adobe’s July and August 2026 security updates installed. Even with the hotfix in place, a store that was attacked before it went in still needs to be checked.

How many stores are affected?

Every store running a current version of Magento Open Source or Adobe Commerce, which is well over 100,000 stores worldwide.

Is there an official fix from Adobe?

Yes. Adobe published an emergency hotfix on September 7 (bulletin APSB26-146, CVE-2026-75650, the highest severity rating). It ships as a composer patch, not a full release, and Adobe also requires rotating your encryption key and credentials.

Is the fix available for my version?

The hotfix covers Magento Open Source 2.4.6 to 2.4.9 and Adobe Commerce 2.4.4 to 2.4.9. Magento Open Source stores on 2.4.5 or older get no patch from Adobe. For those, temporary protection buys time, and an upgrade closes the hole for good. For Magento 2.2.0 to 2.4.3, scandiweb has rebuilt Adobe’s hotfix in the meantime; download the patch on this page.

How do I know if my store has been hacked?

From the outside you often cannot tell. Known signs include unexpected “Payment Transaction Failed Reminder” emails, unfamiliar background processes on the server, new scheduled tasks, and unknown files in the report and temp folders. Someone needs to look at the server. The free security consultation on this page is the first step: it tells our engineers what to look at before the call.

What should I do right now?

Three things: install Adobe’s hotfix and rotate your encryption key and credentials, have someone check the store for signs of compromise, and test cart and checkout afterwards. If you have a Magento partner, ask them today. If not, start with the free security consultation on this page or book a call.

Book a call
I installed the patch but still get “Payment Transaction Failed” emails. Is the store hacked?

Not necessarily. On a patched store, an unauthenticated request to the PayPal checkout API can still trigger that email with no payment behind it, so the messages alone are not proof of a break-in. Treat them as a reason to check the server, not as proof either way.

Are the attacks still going on?

Yes. New variants have appeared since the hotfix, with different file names and hiding places, and stores were still being compromised in the second week of September. A store that was online and unpatched between September 4 and the day it was patched needs a check, not just the patch.

Do I need to take my store offline?

Usually not. Temporary protection can be put in place while the store keeps selling. Taking a store offline is a last resort for a store that is confirmed compromised.

Does installing the patch make my store safe?

It closes the hole for new attacks. It does not remove a backdoor planted earlier, and it does not undo credentials an attacker already read. That is why Adobe requires rotating the encryption key and every credential it protected, and why the check for compromise still matters.

Does this affect Hyvä, PWA, or headless stores?

Yes. The flaw sits in the Magento core, not in the theme or frontend. The attack goes through an API that headless and PWA storefronts rely on, so switching that API off is not an option there and protection has to be more targeted.

I am not a scandiweb client. Can you help?

Yes. Start with the free security consultation on this page or book a call. If your store needs work, we agree on the scope with you first.

Book a call
Talk to our team

Not sure what your store needs?

Speak with our Magento security team about your current protection, the checks your store needs, and how to respond to StyleSmuggler.

Managed Magento hosting

Ongoing protection with ReadyMage

ReadyMage is scandiweb’s managed hosting for Magento and Adobe Commerce, with malware protection, a firewall, and DDoS defense built in.

Talk to us about how your hosting can support your store’s security beyond this incident.