Active Exploitation of Magento Zero-Day Vulnerability 'StyleSmuggler'

Active Exploitation of Magento Zero-Day Vulnerability 'StyleSmuggler'

First seen 5 Sep 2026, 21:03 UTC SansecThehackernews 73.7

Article Content

Browse articles
ThreatCluster

A new unpatched vulnerability, named StyleSmuggler, has been discovered in Magento Open Source and Adobe Commerce, allowing unauthenticated attackers to execute remote code. The attacks began on September 4, 2026, and all current versions, including 2.4.9, are affected. Sansec, the Dutch e-commerce security company that identified the flaw, reported that the vulnerability exploits Magento's template system to inject malicious code. The first known victim was running version 2.4.6-p15 with the latest security patches applied. As of September 5, 2026, Adobe has not released an advisory or patch, with a security release scheduled for September 8. Sansec has advised merchants to block attacks by deploying their Shield product or temporarily disabling GraphQL until a fix is available. The exploit can lead to persistent backdoors being installed on compromised servers. Sansec has also released an eComscan tool to help detect and terminate malicious processes associated with the attack.

Key Points: • StyleSmuggler is a zero-day vulnerability affecting all current Magento versions. • Attacks began on September 4, 2026, with no patch or advisory from Adobe as of September 5. • Merchants are advised to disable GraphQL or use Sansec Shield to mitigate the threat.

Ask AI about this cluster

Timeline

2025-09-09
CVE-2025-54236 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-04
Attacks exploiting StyleSmuggler begin
Sansec reports that attacks leveraging the StyleSmuggler vulnerability started on September 4, 2026.
Sansec
2026-09-05
Sansec publishes advisory on StyleSmuggler
Sansec releases details about the StyleSmuggler vulnerability, outlining its attack method and impact.
Sansec
2026-09-05
The Hacker News reports on the vulnerability
The Hacker News confirms the existence of the StyleSmuggler vulnerability and its exploitation in the wild.
The Hacker News
2026-09-08
Adobe's scheduled security release
Adobe is expected to release a security update, but it is unclear if it will address the StyleSmuggler vulnerability.
The Hacker News