Dutch e-commerce security company Sansec reported on September 5 that attackers are actively exploiting a new, unpatched vulnerability in Magento Open Source and Adobe Commerce. This zero-day, dubbed "StyleSmuggler," allows malicious code execution on an online store's server without requiring authentication. Sansec discovered the flaw and noted that attacks began on September 4, prompting an early public disclosure due to ongoing compromises.
A successful exploit of StyleSmuggler grants attackers code execution privileges on the server and installs a persistent backdoor. Sansec confirmed that all current versions of Magento Open Source are affected, including 2.4.9, and successfully reproduced the unauthenticated chain on clean installations of versions 2.4.7, 2.4.8, and 2.4.9. The first identified victim was running version 2.4.6-p15 with the latest available security updates from Adobe.
As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround for the StyleSmuggler vulnerability. Adobe's next scheduled security release is on September 8, but it is unknown if this bug will be addressed. Sansec's interim advice for affected stores is to temporarily disable GraphQL until a fix is released. Disrex Group, a Magento hosting company, independently confirmed exploitation on two compromised Magento Open Source stores, noting that headless and progressive web app storefronts typically require GraphQL.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Adobe released patches for over 170 vulnerabilities across its products, including a critical zero-day code injection flaw (CVE-2026-75650) in Adobe Commerce and Magento Open Source that has been actively exploited. The vulnerability allows unauthenticated remote code execution and has been used by attackers to deploy backdoors and web shells in online stores. Users are advised to apply fixes immediately and rotate encryption keys and credentials.
Adobe released an emergency security fix for CVE-2026-75650, a critical zero-day vulnerability dubbed StyleSmuggler, affecting multiple versions of Magento and Adobe Commerce. This flaw has been actively exploited since at least September 4 to install backdoors on vulnerable e-commerce servers, allowing for arbitrary code execution.
Adobe released security patches for a critical zero-day vulnerability, CVE-2026-75650, affecting Adobe Commerce and Magento Open Source, which has been actively exploited since September 4, 2026. This flaw allows arbitrary code execution through PHP code injection in Magento's template system, leading to the deployment of Rust backdoors and PHP web shells on compromised e-commerce sites.
A zero-day vulnerability named "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is actively being exploited to install a Rust-based Linux backdoor. This vulnerability allows attackers to inject PHP code through Magento's template system, leading to code execution and persistence on affected e-commerce sites.
A zero-day vulnerability, dubbed StyleSmuggler, in Adobe Commerce and Magento e-commerce platforms is being actively exploited to inject PHP code and install backdoors on online stores. This flaw allows attackers to achieve remote code execution without user interaction, posing a significant risk to affected e-commerce businesses.
A new unpatched zero-day vulnerability, named StyleSmuggler, in Magento Open Source and Adobe Commerce is being actively exploited to install backdoors on online store servers. The flaw allows attackers to execute malicious code without authentication, affecting all current versions including 2.4.9. Adobe has not yet released a patch or advisory, leaving stores vulnerable to compromise.