StyleSmuggler: The Magento Zero-Day Behind New Store Attacks
Brief
StyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched.
A new zero-day flaw, dubbed StyleSmuggler, in Magento and Adobe Commerce is under active attack, giving unauthenticated attackers a path to run code on vulnerable online stores. Sansec researchers say it affects current Magento Open Source releases, including 2.
- 7, 2.
- 8 and 2.
- 9. According to the experts, exploitation began on September 4.
“Sansec discovered StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. All current versions are affected, including 2.
- 9.” reads the report published by Sansec. “Attacks started September 4th. Sansec is rolling out emergency mitigation.”
This is not a routine patch-cycle problem.
