← All stories
● Covered by 1 source · 1 reportHigh impact1 negative

Unpatched Magento and Adobe Commerce Zero-Day Actively Exploited to Backdoor Online Stores

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • New zero-day vulnerability "StyleSmuggler" exploited in Magento/Adobe Commerce.
  • Allows unauthenticated code execution and persistent backdoor installation.
  • All current versions, including 2.4.9, are affected.
  • Adobe has not released a patch or advisory as of September 6.

Active Exploitation of New Zero-Day

Dutch e-commerce security company Sansec reported on September 5 that attackers are actively exploiting a new, unpatched vulnerability in Magento Open Source and Adobe Commerce. This zero-day, dubbed "StyleSmuggler," allows malicious code execution on an online store's server without requiring authentication. Sansec discovered the flaw and noted that attacks began on September 4, prompting an early public disclosure due to ongoing compromises.

Vulnerability Details and Impact

A successful exploit of StyleSmuggler grants attackers code execution privileges on the server and installs a persistent backdoor. Sansec confirmed that all current versions of Magento Open Source are affected, including 2.4.9, and successfully reproduced the unauthenticated chain on clean installations of versions 2.4.7, 2.4.8, and 2.4.9. The first identified victim was running version 2.4.6-p15 with the latest available security updates from Adobe.

Adobe's Response and Interim Advice

As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround for the StyleSmuggler vulnerability. Adobe's next scheduled security release is on September 8, but it is unknown if this bug will be addressed. Sansec's interim advice for affected stores is to temporarily disable GraphQL until a fix is released. Disrex Group, a Magento hosting company, independently confirmed exploitation on two compromised Magento Open Source stores, noting that headless and progressive web app storefronts typically require GraphQL.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~15 min · 12 stories · Sep 05

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A new unpatched zero-day vulnerability, named StyleSmuggler, in Magento Open Source and Adobe Commerce is being actively exploited to install backdoors on online store servers. The flaw allows attackers to execute malicious code without authentication, affecting all current versions including 2.4.9. Adobe has not yet released a patch or advisory, leaving stores vulnerable to compromise.