Magento Zero-Day Exploited for Store Backdoors
Threat actors are actively exploiting a newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce platforms, allowing them to install persistent backdoors and compromise online stores. The flaw, named StyleSmuggler, enables attackers to execute malicious code on vulnerable servers without requiring any authentication. Dutch e-commerce security firm Sansec discovered the vulnerability and disclosed it on September 5, 2026, stating that active attacks began the previous day, September 4, 2026. Sansec released its findings early due to the ongoing compromise of online stores. As of September 7, 2026, Adobe has not issued an official patch, advisory, or workaround for the vulnerability. The company's most recent security bulletin index still dates to August 11, 2026. Adobe's next scheduled security release is September 8, 2026, but it remains uncertain if this vulnerability will be addressed. The StyleSmuggler vulnerability affects all current versions of Magento Open Source and Adobe Commerce, including the latest release, 2.4.9. Sansec successfully reproduced the attack chain on clean installations of Magento Open Source versions 2.4.7, 2.4.8, and 2.4.9.