StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

From the source: Tenable Blog

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can…

Read the full story on Tenable Blog
Originally published by Tenable Blog on 9 Sept 2026. Techarda links to the original rather than republishing it. Read the full article →

Have you worked with this?

The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.

Start the discussion

More from Tenable

Recent updates from Tenable, so you can tell whether this is a one-off or part of a pattern.

All Tenable news →
SecurityNew

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities

There are reportedly two unpatched zero-day Citrix NetScaler vulnerabilities capable of enabling remote code execution that have been actively exploited in the wild, with no patches available at this time. Key takeaways Reports indicate that there are two critical zero-day vulnerabilities in Citrix NetScaler. The reports originate from a pre-notification sent out ahead of public disclosure, so…

Tenable·via Tenable Blog
Security

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at…

Tenable·via Tenable Blog
Security

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture. Key takeaways The Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series…

Tenable·via Tenable Blog

More in Security

What other companies in Security are doing. The category page shows who’s active, side by side.

Compare companies in Security →
SecurityWhy it matters

Threat Actors Use Google Ads To Target Ledger Users

In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…

Zscaler·via Zscaler ThreatLabz
SecurityNew

The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches

A routine package install can open the door to a cloud breach. Learn how attackers exploit developer credentials. Discover practical steps to contain exposure and protect your cloud environment.

Qualys·via Qualys Blog
SecurityNew

Next.js applications, powered by Vite: introducing Vinext 1.0

Vinext 1.0 graduates from an AI experiment to a production-ready framework, letting developers run Next.js apps on Vite. This release brings advanced cache warming, broader compatibility, and an automated testing pipeline.

Cloudflare·via Cloudflare Blog
SecurityNew

Introducing cf: the agentic CLI for the entire Cloudflare API

We are releasing cf, our new command-line tool that mirrors the entire Cloudflare API and supports programmatic TypeScript configuration. We are also open-sourcing Forge, our internal SDK generator.

Cloudflare·via Cloudflare Blog