Commerce Platforms & DTC
Adobe Commerce

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports. Dubbed StyleSmuggler, the security defect enables attackers to inject PHP code into Magento’s template system and evade detection by using the ‘styles’ properties. According to Sansec, the attack works in two stages: first,
cybernoz.com
September 8, 2026
3
Cybernoz
WHAT HAPPENED
SecurityWeek September 8, 2026 2 min read Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports. Dubbed StyleSmuggler , the security defect enables attackers to inject PHP code into Magento’s template system and evade detection by using the ‘styles’ properties. According to Sansec, the attack works in two stages: first, the PHP code is injected by generating a failure report, and then Magento executes the code via a failed payment email. 9, and has been exploited against deployments running the July and August 2026 patches, Sansec says. Successful attacks have been deploying a backdoor against Commerce and Magento stores.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY