THREAT OPS › Threat News › StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited
StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited
<h1>StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited</h1> <p>Attackers are actively exploiting an unpatched zero-day vulnerability in <strong>Magento Open Source</strong> and <strong>Adobe Commerce</strong> that allows unauthenticated remote code execution and persistent backdoor installation. Dutch e-commerce security firm Sansec discovered the flaw, named <strong>StyleSmugg
MITRE ATT&CK techniques
Indicators of compromise
- https://helpx.adobe.com/security/security-bulletin.htmlurl
- https://sansec.io/research/stylesmugglerurl
- https://www.disrex.nl/blogs/stylesmuggler-magento-zero-dayurl
Original source: https://socradar.io/blog/stylesmuggler-magento-adobe-commerce-0day/
Same event, other sources
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storesthehackernews · 2026-09-05
- Magento StyleSmuggler zero-day exploited to deploy Linux backdoorbleepingcomputer · 2026-09-07