Back to blog
Adobe Commerce zero-day: patch in hours, not weeks
October 6, 2026Security

Adobe Commerce zero-day: patch in hours, not weeks

The SMART SOLID SOLUTIONS team



On September 4, 2026, attackers began exploiting an Adobe Commerce flaw nobody knew existed yet. The emergency fix landed on the 7th; the monthly bulletin on the 8th added eight more critical vulnerabilities. A month on, the episode deserves a cold read — less for the CVE numbers than for what it reveals about your organisation: the gap between a patch being published and being applied has become a survival metric.


Attackers were three days ahead


Chronology first. The campaign, which Sansec dubbed StyleSmuggler, started on September 4: several groups were already planting backdoors and web shells by abusing a template-engine injection, triggered through a standard transactional email — the payment-failure reminder — with no action required from the victim (SecurityWeek's account). Adobe responded on September 7 with an out-of-cycle fix, bulletin APSB26-146: CVE-2026-75650 carries the maximum CVSS score of 10.0 and allows unauthenticated remote code execution. Affected: Adobe Commerce 2.4.4 through 2.4.9, Magento Open Source 2.4.6 through 2.4.9, and the B2B extension 1.3.3 through 1.5.3 — in plain terms, almost the entire installed base, even stores current as of August.


The next day, the monthly bulletin APSB26-138 fixed eight more flaws, every one rated critical: two stored XSS issues scored 9.3, five authorisation defects, one path traversal. Six of the eight can be exploited without any account.


The two-patch trap


One operational detail matters: the emergency fix is not part of the monthly train. Adobe states it installs separately — applying the September level without the hotfix leaves the only actively exploited hole open, and the hotfix alone does not cover the other eight. Since 2026, grouped patches ship monthly and are named by date (2.4.9-2026-sep, for instance) rather than with p-numbers. More readable — but it assumes someone, on your team or at your integrator, actually reads the bulletins and can tell a priority hotfix from a routine deadline.


The window has closed


Same season last year: SessionReaper (CVE-2025-54236), fixed on September 9, 2025. Mass attacks waited six weeks; at that point only 38% of stores were patched, and the automated waves ended up probing more than one store in two worldwide, according to figures Sansec published at the time. In 2026 the script flipped: exploitation preceded the fix by three days. The conclusion is blunt but simple — patching next sprint is no longer a security policy; it is a bet against automated adversaries.


What this demands from your organisation


Three very practical consequences, seen from the architect's chair:


  • A written patch SLA. Actively exploited hotfix: applied within hours. Critical bulletin: within days. Name who reads the bulletins, who decides, who applies, who verifies — a patch without an owner always waits.
  • An architecture that makes patching cheap. A staging environment faithful to production, automated tests on the buying journeys, repeatable zero-downtime deployment. The real cost of a patch is the fear of breaking something; that fear is built — or dismantled — by your architecture.
  • Enough to hold the first hours. A web application firewall in front of the admin and the APIs, file-integrity monitoring, a regular review of admin accounts. And after an exploited zero-day, patching is not enough: look for traces of a visit prior to the fix — web shells, unknown accounts, scheduled tasks, modified modules.

The October checklist


  • Record the exact patch level of every environment, B2B extension included: if it is older than September 2026, you are exposed.
  • Confirm the CVE-2026-75650 hotfix is applied everywhere — production, staging, any demo environment reachable from the internet.
  • Have any store that remained vulnerable after September 4 inspected as if it had been visited: exploitation started before the fix existed.
  • Write the SLA, then time yourselves on the October train: it is the cheapest full-scale drill on the market.

A security bulletin is, at bottom, a free test of your delivery chain. Organisations that ship a patch within hours have healthy architecture and governance; those that take weeks discover, one September or another, that technical debt is also paid in security incidents.

Our team can help you.

Let’s discuss your project.