StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento - DEV Community
CVE-2026-75650 let attackers turn a Magento payment failure email into unauthenticated RCE and install a Rust backdoor that hides as a kernel thread.