Unpatched Magento Zero-Day Actively Backdooring Stores, No Fix Available Yet
Dutch e-commerce security firm Sansec disclosed a critical zero-day vulnerability on September 5, 2026, dubbed StyleSmuggler, affecting all current versions of Magento Open Source and Adobe Commerce. The flaw allows unauthenticated remote code execution and installs a persistent backdoor, with active exploitation observed in the wild since September 4. As of September 6, Adobe has issued no patch, CVE, or official advisory, and being fully up to date on security updates did not protect affected stores. Two confirmed compromised stores — running versions 2.4.8 and 2.4.7-p2 respectively — were breached within hours of the first known attack, before any defensive rules existed. The only interim mitigation Sansec recommends for stores without its Shield product is to disable GraphQL, though this is not viable for headless or PWA storefronts; Adobe's next scheduled security release is September 8.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in