A critical vulnerability in Adobe Commerce and Magento was already being exploited before a hotfix became available. If you haven't already acted against CVE-2026-75650, known as "StyleSmuggler", it is crucial that you do.
StyleSmuggler is an unauthenticated remote code execution flaw which gives attackers deep access to your store and customers' data. According to CrowdSec (with emphasis added):
Code execution on a Magento server means the attacker sits where card data is entered, customer records are stored, and the database password lives. Sansec found a Rust backdoor disguised as system processes that beacons to its operators over traffic shaped like time-sync (NTP) packets, and a second actor dropping a PHP web shell into the product image cache. That is the setup for card skimming and for reselling access to the store. CrowdSec CTI classifies 98% of the observed intent as infrastructure takeover.
Affected versions
Essentially every currently-supported version of Magento or Adobe Commerce is affected.
Magento Open Source 2.4.6 to 2.4.9.
Adobe Commerce 2.4.4 to 2.4.9.
Adobe Commerce B2B 1.3.3 to 1.5.3.
If you are running anything older, it is already out of support and you should expect it to also be affected. The safest course of action is to update to a supported version before applying the hotfix.
To start taking action, see Adobe's security bulletin, including the hotfix.
Even if your server is managed, this is an application update for you to make
Whether your server is managed or unmanaged, this is an update that you need to make. Managed Services cover the entire infrastructure layer (like patching Linux vulnerabilities in their hundreds), but not the application layer.
Please apply the hotfix to Magento or Adobe Commerce as soon as you possibly can.