StratosAlly – Cybersecurity for digital safety

Hackers Are Actively Exploiting a Magento and Adobe Commerce 0-Day

Picture of StratosAlly

StratosAlly

Hackers Are Actively Exploiting a Magento and Adobe Commerce 0-Day

Online stores running Magento or Adobe Commerce are facing a serious new threat, and this time, waiting for the next routine security update may not be enough.

Security researchers at Sansec have discovered a new zero-day vulnerability, dubbed “StyleSmuggler,” that is already being exploited in the wild. The flaw allows attackers to execute malicious code remotely on vulnerable e-commerce servers without needing to authenticate first.

What makes the situation particularly concerning is that there is currently no official patch available. Sansec said it decided to disclose the vulnerability early because Magento stores were already being compromised.

The researchers first observed attacks on September 4, 2026, and were able to reproduce the attack chain on clean installations of Magento Open Source versions 2.4.7, 2.4.8 and 2.4.9. The vulnerability also affects the latest 2.4.9 release, meaning simply running the newest version does not necessarily protect a store.

StyleSmuggler abuses Magento’s template system to inject malicious PHP code. Attackers can then trigger Magento to execute that code through a failed-payment email workflow.

Once inside, attackers can establish persistence on the server. Sansec observed a malicious background process disguised as a legitimate Linux kernel process, along with a cron job designed to restart the malware if it is removed.

In other words, this isn’t just a vulnerability that could theoretically be exploited. Attackers are already using it to gain a foothold inside real online stores.

The situation is further complicated by the absence of an official CVE or vendor fix at the time of reporting. Adobe’s next scheduled security bulletin is expected on September 8, but it remains unclear whether it will address StyleSmuggler.

Sansec recommends temporarily disabling GraphQL if possible until an official fix becomes available. Merchants should also scan their systems for signs of compromise and look for unusual processes, unexpected cron jobs andsuspicious activity in Magento logs.

Let’s refine your stalking skills; go through our Instagram and LinkedIn.

more Related articles