← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 7, 2026 · 06:16via CyberPress

Hackers Exploit StyleSmuggler Magento and Adobe Commerce Zero-Day for Unauthenticated RCE

Brief

A newly disclosed actively exploited zero-day vulnerability in Magento and Adobe Commerce allows unauthenticated attackers to execute code remotely on affected e-commerce stores.

The flaw, named StyleSmuggler, was discovered by Sansec’s Forensics Team, which warned that exploitation began on September 4. The issue is currently unpatched and impacts all supported Magento and Adobe Commerce versions, including Magento Open Source 2.

  • 9.

Sansec reproduced the complete unauthenticated attack chain on clean Magento Open Source installations of 2.

  • 7, 2.
  • 8, and 2.
  • 9.

Hackers Exploit StyleSmuggler Magento and Adobe Commerce Zero-Day

Sansec also identified a victim running Magento 2.

  • 6-p15 with July and August 2026 security patches installed, despite the system reporting a clean security:patch-status result.
Read more on CyberPress