Scott Robinson Technical Lead

Series

StyleSmuggler / CVE-2026-75650

Everything written here about StyleSmuggler, the Magento admin CSS injection tracked as CVE-2026-75650: what Adobe changed in the patches, what the Fastly rules broke, and what to do on a store that was already hit.

In this series

All posts →
08/09/2026 magento CVE-2026-75650 / APSB26-146: Magento built the object before it checked the class typeAdobe shipped the same eight-file fix to every supported Magento version: two ordering bugs, an untyped request parameter and three ACL checks that moved 7m 10/09/2026 magento Removing Adobe's CVE-2026-75650 Fastly Rules That Break Admin Page SavesThe accord-rce VCL snippets Adobe pushed for APSB26-146 return a 403 on any page containing a template directive, which is most of them: how to read, clone, delete and validate your way back out 4m 11/09/2026 magento StyleSmuggler Remediation: Invalidating Every Magento Admin Session and PasswordPatching StyleSmuggler does not evict anyone already holding a session cookie: the two statements that do, what admin_user_session.status actually means and how to get back in afterwards 6m