StyleSmuggler Turns Adobe Commerce’s Own Template Engine Into an Unauthenticated RCE Chain
CVE-2026-75650 lets attackers inject PHP through Magento's email template system, then triggers execution automatically. Multiple threat groups are already inside. The authentication gap has reached the payment layer.