Hackers Exploit StyleSmuggler Magento and Adobe Commerce Zero-Day for Unauthenticated RCE
Brief
A newly disclosed actively exploited zero-day vulnerability in Magento and Adobe Commerce allows unauthenticated attackers to execute code remotely on affected e-commerce stores.
The flaw, named StyleSmuggler, was discovered by Sansec’s Forensics Team, which warned that exploitation began on September 4. The issue is currently unpatched and impacts all supported Magento and Adobe Commerce versions, including Magento Open Source 2.
- 9.
Sansec reproduced the complete unauthenticated attack chain on clean Magento Open Source installations of 2.
- 7, 2.
- 8, and 2.
- 9.
Hackers Exploit StyleSmuggler Magento and Adobe Commerce Zero-Day
Sansec also identified a victim running Magento 2.
- 6-p15 with July and August 2026 security patches installed, despite the system reporting a clean security:patch-status result.
