Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Executive Summary

Attackers are exploiting a newly discovered, unpatched vulnerability in Magento Open Source and Adobe Commerce, dubbed StyleSmuggler, that allows them to execute malicious code on a store’s server without authentication. The flaw was identified by Dutch security firm Sansec, and attacks began on September 4, 2024.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-05T20:14:47+00:00 - Category: threat-intel

Original Description: Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

"Difficulties are things that show a person what they are."

— Epictetus
Source: The Hacker News