Critical

Magento, Adobe Commerce, StyleSmuggler, Zero-Day, E-Commerce Security, Remote Code Execution, GraphQL

Magento StyleSmuggler Zero-Day Exploited, No Patch Yet

Magento StyleSmuggler is an unpatched, actively exploited zero-day giving unauthenticated code execution and a backdoor on Adobe Commerce and Magento Open Source stores.

Magento StyleSmuggler is an unpatched, actively exploited zero-day in Magento Open Source and Adobe Commerce that lets an attacker run code on an online store's server without logging in and installs a persistent backdoor. Dutch e-commerce security firm Sansec discovered the flaw, named it StyleSmuggler, and published early on September 5, 2026 because "stores are being compromised right now." Attacks began on September 4. As of September 6, Adobe had not released an advisory, a CVE identifier, a patch, or a workaround, and its security bulletin index listed nothing after the August 11 update.

Sansec said all current versions are affected, including the latest 2.4.9, and reproduced the full unauthenticated exploit chain on clean Magento Open Source installs of 2.4.7, 2.4.8, and 2.4.9. Its first victim was running 2.4.6-p15 with Adobe's July and August 2026 updates applied, the newest patch level Adobe offers for that release line, which means being fully patched did not help. A successful attack yields code execution on the store server and a persistent backdoor.

The exploitation is not just Sansec's finding. Magento hosting firm Disrex Group independently handled two compromised Magento Open Source stores, and a third that was attacked but not breached, publishing an incident-response repository on September 5 based on real attack traffic. Adobe's next scheduled security release is September 8, and it is not yet confirmed whether that release will fix this bug.

How do you protect a Magento store before a patch exists?

Sansec's interim advice for stores not running its Shield product is to temporarily disable GraphQL until Adobe ships a fix. Disrex notes the practical catch: headless and progressive web app storefronts require GraphQL, while most classic and Hyva storefronts do not, so the mitigation is viable for many stores but not all. Teams should also hunt for signs of an already-installed backdoor rather than assume disabling GraphQL alone is enough, because attacks have been live since September 4.

Why is an e-commerce zero-day with no CVE so dangerous?

Because there is no vendor advisory to trigger normal patch workflows, no CVE to track, and no patch to apply, yet exploitation is already happening at scale against a platform that processes payments. The gap between "being compromised right now" and "Adobe has published nothing" is exactly the window attackers want. A store owner waiting for an official CVE before acting is, in effect, choosing to stay exploitable through an active campaign.

Detail

Value

Name

StyleSmuggler

CVE

None assigned as of September 6, 2026

Impact

Unauthenticated RCE plus persistent backdoor

Affected

Magento Open Source and Adobe Commerce, all current versions incl 2.4.9

Exploited

Yes, in the wild since September 4, 2026

Interim mitigation

Temporarily disable GraphQL; hunt for backdoors

Our read

StyleSmuggler is a textbook case of why waiting for a CVE is the wrong trigger for action. The evidence of exploitation is independent and concrete: two security firms, live attack traffic, and confirmed backdoors, all before the vendor has said a word. When a payment-handling platform has an unauthenticated code-execution bug under active attack, the defensible move is to reduce exposure immediately, disabling GraphQL where storefront architecture allows, and to assume compromise and hunt for the backdoor rather than trust a clean patch level. Continuous verification means checking whether you are already breached, not only whether a patch is available.

Reporting by The Hacker News; discovery and exploitation detail per Sansec; independent incident confirmation per Disrex Group. Sources linked above.

Related: What is a zero-day? and What is a software supply chain attack?.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.