StyleSmuggler Turns Adobe Commerce’s Own Template Engine Into an Unauthenticated RCE Chain
Nine 48-byte datagrams, spaced 10 milliseconds apart, arrive every 60 seconds. To a standard network monitor, this looks like routine NTP traffic. To the Rust-based implant behind CVE-2026-75650, it is a heartbeat. This is StyleSmuggler, a critical vulnerability in Adobe Commerce and Magento 2.4.4 through 2.4.9 that has turned the platform’s own template-processing logic into…