{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-73BC735F",
  "slug": "cve-2026-75650-adobe-commerce-stylesmuggler-template-rce",
  "title": "Adobe Commerce StyleSmuggler template RCE (unauth)",
  "aliases": [
    "CVE-2026-75650",
    "StyleSmuggler",
    "Adobe Commerce Magento template RCE"
  ],
  "summary": "Adobe Commerce / Magento Open Source are affected by improper neutralization of special elements in a template engine (CWE-1336) that can lead to arbitrary code execution. Exploitation does not require authentication per Adobe's advisory. Apply APSB26-146 and the patched Commerce/Magento builds.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Exact vulnerable version floors are stated in APSB26-146; the evidence pack lists product names without numeric ranges, so operators must confirm against the live Adobe bulletin for their train.",
  "firstObservedAt": "2026-09-07T20:17:16.761Z",
  "lastObservedAt": "2026-09-07T20:23:21.462Z",
  "publishedAt": "2026-09-20T19:57:45.963Z",
  "reviewedAt": "2026-09-20T19:57:41.779Z",
  "expiresAt": "2026-09-07T20:23:21.462Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "adobe-apsb",
      "label": "Adobe APSB26-146 Magento / Commerce advisory",
      "url": "https://helpx.adobe.com/security/products/magento/apsb26-146.html",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-09-07T20:17:16.761Z"
    },
    {
      "id": "nvd",
      "label": "NVD CVE-2026-75650",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75650",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-07T20:23:21.462Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up (StyleSmuggler)",
      "url": "https://hol.org/blog/cve-2026-75650-adobe-commerce-stylesmuggler-template-rce",
      "sourceType": "other_primary",
      "observedAt": "2026-09-07T00:00:00.000Z"
    }
  ],
  "artifacts": [
    {
      "id": "adobe-commerce",
      "artifactClass": "package",
      "ecosystem": "adobe",
      "name": "Adobe Commerce",
      "version": "before APSB26-146 patched builds",
      "defanged": false
    },
    {
      "id": "magento-open-source",
      "artifactClass": "package",
      "ecosystem": "adobe",
      "name": "Magento Open Source",
      "version": "before APSB26-146 patched builds",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-07T20:17:16.761Z",
      "eventType": "disclosure",
      "summary": "Adobe published APSB26-146 covering CVE-2026-75650 template-engine RCE in Commerce/Magento.",
      "sourceIds": [
        "adobe-apsb",
        "nvd"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-07T21:00:00.000Z",
      "eventType": "other",
      "summary": "HOL Guard published StyleSmuggler operator blog coverage for CVE-2026-75650.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "One campaign covers CVE-2026-75650; prefer StyleSmuggler blog slug over the sibling Magento template-RCE post.",
    "Numeric version floors come from APSB26-146 — this campaign does not invent fixed builds beyond the Adobe bulletin.",
    "Adobe Commerce B2B is also in scope per the pack; confirm B2B patch lines in APSB26-146."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-75650-adobe-commerce-stylesmuggler-template-rce/corrections"
}
