Back to feed

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

2 min
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

This digest was compiled by AI from multiple sources — links to the originals are below.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that allows unauthenticated code execution and backdoor installation, Dutch security firm Sansec said on September 5. Sansec named the flaw StyleSmuggler and said attacks began September 4, with all current versions affected including 2.4.9. Adobe has not yet released a patch, advisory, or workaround, and its next scheduled security release is September 8.

Key Facts

  • Sansec named the vulnerability StyleSmuggler and said attacks began on September 4, 2026.
  • All current Magento Open Source and Adobe Commerce versions are affected, including 2.4.9.
  • Sansec reproduced the full unauthenticated attack chain on clean Magento Open Source installations of 2.4.7, 2.4.8, and 2.4.9.
  • Adobe's next scheduled security release is September 8, 2026, and it is unknown whether it will address this flaw.
  • Disrex Group handled two stores compromised on September 5 and a third that was attacked but not breached.

The Vulnerability

The flaw allows attackers to execute malicious code on a store's server without logging in and install a persistent backdoor. Sansec reproduced the full unauthenticated chain on clean Magento Open Source installations of versions 2.4.7, 2.4.8, and 2.4.9. The first victim ran Magento 2.4.6-p15 with Adobe's July and August 2026 security updates applied, the latest patch level for that release line. Sansec has not published a reproduction on Adobe Commerce or Adobe Commerce on Cloud, and Adobe has not confirmed which versions are affected.

Exploitation Evidence

Disrex Group, a Magento hosting and development company, published an incident-response repository on September 5 documenting two stores compromised that day and a third that was attacked but not breached. One compromised store ran Magento 2.4.7-p2, a patch level dated August 2024 and eight levels behind the current 2.4.7-p10. The store labeled Store A was a Sansec Shield customer and was hit at 23:10 UTC on September 4, hours before Sansec's first blocking rules went live. Disrex's web-server rules are based on attack traffic captured on one of the compromised stores.

Mitigation and Response

Sansec advises stores not running its Shield product to disable GraphQL until Adobe releases a temporary fix. Disrex notes that headless and progressive web app storefronts require GraphQL, whereas most classic and Hyvä storefronts do not. Adobe has not published an advisory, CVE identifier, patch, or workaround as of September 6, and its security bulletin index lists nothing after the August 11 update. Adobe's next scheduled security release is September 8, and it is not yet known whether that release will cover this bug.

1 source

Time · lag behind first