Cybersecurity firm Sansec discovered a zero-day vulnerability named StyleSmuggler targeting Adobe Commerce and Magento platforms. Attackers began exploiting the flaw on September 4 to install backdoors in online stores. The vulnerability allows remote code execution and full system control.
The exploit affects Magento versions 2.4.7 through 2.4.9. It bypasses security patches released as recently as July and August 2026.
This two-stage attack first injects malicious code into the system. Attackers then trigger execution via a failed payment transaction email. The flaw compromises e-commerce integrity and customer data security.