StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited
Brief
StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited
Attackers are actively exploiting an unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce that allows unauthenticated remote code execution and persistent backdoor installation. Dutch e-commerce security firm Sansec discovered the flaw, named StyleSmuggler , and published an early advisory on September 5, 2026, warning that online stores were already being compromised.
As of September 7, 2026, Adobe has not issued a CVE identifier, an advisory, a patch, or a workaround.
What Is StyleSmuggler?
StyleSmuggler is an unauthenticated remote code execution vulnerability affecting Magento Open Source and Adobe Commerce. The flaw allows an attacker to execute arbitrary code on a store’s server without any authentication, then install a persistent backdoor.
