WHAT HAPPENED
StyleSmuggler: The Magento Zero-Day Behind New Store Attacks Pierluigi Paganini September 07, 2026 StyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched. A new zero-day flaw, dubbed StyleSmuggler, in Magento and Adobe Commerce is under active attack, giving unauthenticated attackers a path to run code on vulnerable online stores. Sansec researchers say it affects current Magento Open Source releases, including 2. “Sansec discovered StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. Sansec reproduced the full attack chain on clean installations and observed a first victim running Magento 2.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY