........................................................................
CVE-2026-75650 "StyleSmuggler" is a CVSS 10.0 unauthenticated remote code execution flaw in Adobe Commerce 2.4.4 to 2.4.9 and Magento Open Source 2.4.6 to 2.4.9. It was exploited three days before Adobe's fix. CrowdSec has observed 500 unique IP addresses sending matching requests since September 9, 2026. Apply hotfix VULN-39341 now, then check the store for backdoors.
Two-thirds of the addresses are American home connections: Of the 410 addresses CrowdSec CTI links to this CVE, 265 are in the United States, most of them on Comcast, Charter, Verizon, AT&T, and T-Mobile lines. Yet the US produces only 22% of signals. Many home addresses, each sending a few requests, are part of residential proxy networks or compromised home devices.
Oopsie
\
........................................................................
........................................................................

........................................................................

........................................................................
Previous | First | 1 | Last | Next