{"type":"bundle","id":"bundle--5bf7e962-78f9-52b1-b580-6f266cff221f","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--7313cf07-a7ed-54db-8cf0-632b34f830c0","created":"2026-09-20T19:57:45.963Z","modified":"2026-09-20T19:57:45.963Z","name":"Adobe Commerce StyleSmuggler template RCE (unauth)","description":"Adobe Commerce / Magento Open Source are affected by improper neutralization of special elements in a template engine (CWE-1336) that can lead to arbitrary code execution. Exploitation does not require authentication per Adobe's advisory. Apply APSB26-146 and the patched Commerce/Magento builds.","aliases":["CVE-2026-75650","StyleSmuggler","Adobe Commerce Magento template RCE"],"first_seen":"2026-09-07T20:17:16.761Z","last_seen":"2026-09-07T20:23:21.462Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"Adobe APSB26-146 Magento / Commerce advisory","url":"https://helpx.adobe.com/security/products/magento/apsb26-146.html"},{"source_name":"NVD CVE-2026-75650","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75650"},{"source_name":"HOL Guard operator write-up (StyleSmuggler)","url":"https://hol.org/blog/cve-2026-75650-adobe-commerce-stylesmuggler-template-rce"}]}]}