// hackerlogs
login+ register

Publication

hackerlogs

hackerlogs is an independent publication on the security of AI systems: prompt injection, agentic AI, the model supply chain, and AI red teaming. Explainers, hands-on labs, and threat briefs for practitioners.

LLM AppSecThreat BriefCritical

StyleSmuggler Gave Magento Unauth RCE. The Hotfix Does Not Clean the Store.

StyleSmuggler is CVE-2026-75650, unauthenticated RCE in Magento and Adobe Commerce via the template engine. Sansec saw exploitation from 4 September. Adobe shipped hotfix VULN-39341 as APSB26-146 on 7 September, CVSS 10.0. July and August patches did not stop it. The hotfix does not remove implants, and rotating the encryption key does not revoke stolen credentials.

5 min read