Unpatched Vulnerability in Magento and Adobe Commerce Exploited for Backdoor Attacks

A newly discovered unpatched vulnerability in Magento Open Source and Adobe Commerce is being actively exploited, allowing attackers to execute malicious code on online stores without authentication.

A recently identified unpatched vulnerability in Magento Open Source and Adobe Commerce is being exploited to install backdoors on online stores. The Dutch e-commerce security firm Sansec reported the flaw, named StyleSmuggler, in an advisory published on September 5, 2026.

Details of the Exploit

Sansec noted that attacks began on September 4, 2026, and confirmed that the vulnerability allows attackers to run malicious code on a store’s server without needing to log in. As of September 6, Adobe had not issued an advisory, a CVE identifier, or a patch for the vulnerability. The latest update from Adobe was on August 11, 2026.

Affected Versions

All current versions of Magento, including 2.4.9, are affected. Sansec successfully reproduced the exploit on clean installations of versions 2.4.7, 2.4.8, and 2.4.9. The first known victim was running version 2.4.6-p15, which had received Adobe’s July and August 2026 security updates.

Mitigation Recommendations

Sansec has advised stores not using its Shield product to temporarily disable GraphQL until a fix is released by Adobe. The next scheduled security release from Adobe is on September 8, 2026, but it remains unclear whether this will address the vulnerability. Disrex Group, a Magento hosting company, has reported handling two compromised stores and noted that the patch status was irrelevant in these cases, as both stores were breached within hours of the first exploitation.

Indicators of Compromise

The implant used in these attacks disguises itself as a Linux kernel thread and is installed in a user directory rather than the web root. Sansec has published several indicators of compromise, including specific file paths and process names associated with the backdoor. Disrex has also provided additional insights into the exploit chain and recommended monitoring for unusual activity, such as unexpected bursts of Payment Transaction Failed Reminder emails.

As of now, the full scope of the attacks and the number of affected stores remain unconfirmed. Store owners are encouraged to rotate credentials and monitor their systems closely until a definitive patch is made available.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 384