Thehackernews
Active Exploitation of Magento Zero-Day Vulnerability 'StyleSmuggler'
Article Content
A new unpatched vulnerability, named StyleSmuggler, has been discovered in Magento Open Source and Adobe Commerce, allowing unauthenticated attackers to execute remote code. The attacks began on September 4, 2026, and all current versions, including 2.4.9, are affected. Sansec, the Dutch e-commerce security company that identified the flaw, reported that the vulnerability exploits Magento's template system to inject malicious code. The first known victim was running version 2.4.6-p15 with the latest security patches applied. As of September 5, 2026, Adobe has not released an advisory or patch, with a security release scheduled for September 8. Sansec has advised merchants to block attacks by deploying their Shield product or temporarily disabling GraphQL until a fix is available. The exploit can lead to persistent backdoors being installed on compromised servers. Sansec has also released an eComscan tool to help detect and terminate malicious processes associated with the attack.
Key Points: • StyleSmuggler is a zero-day vulnerability affecting all current Magento versions. • Attacks began on September 4, 2026, with no patch or advisory from Adobe as of September 5. • Merchants are advised to disable GraphQL or use Sansec Shield to mitigate the threat.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.