Dutch e-commerce security company Sansec reported on September 5 that attackers are actively exploiting a new, unpatched vulnerability in Magento Open Source and Adobe Commerce. This zero-day, dubbed "StyleSmuggler," allows malicious code execution on an online store's server without requiring authentication. Sansec discovered the flaw and noted that attacks began on September 4, prompting an early public disclosure due to ongoing compromises.
A successful exploit of StyleSmuggler grants attackers code execution privileges on the server and installs a persistent backdoor. Sansec confirmed that all current versions of Magento Open Source are affected, including 2.4.9, and successfully reproduced the unauthenticated chain on clean installations of versions 2.4.7, 2.4.8, and 2.4.9. The first identified victim was running version 2.4.6-p15 with the latest available security updates from Adobe.
As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround for the StyleSmuggler vulnerability. Adobe's next scheduled security release is on September 8, but it is unknown if this bug will be addressed. Sansec's interim advice for affected stores is to temporarily disable GraphQL until a fix is released. Disrex Group, a Magento hosting company, independently confirmed exploitation on two compromised Magento Open Source stores, noting that headless and progressive web app storefronts typically require GraphQL.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new unpatched zero-day vulnerability, named StyleSmuggler, in Magento Open Source and Adobe Commerce is being actively exploited to install backdoors on online store servers. The flaw allows attackers to execute malicious code without authentication, affecting all current versions including 2.4.9. Adobe has not yet released a patch or advisory, leaving stores vulnerable to compromise.