Attackers are exploiting the unpatched StyleSmuggler flaw in Magento Open Source and Adobe Commerce to execute code on store servers and plant persistent backdoors without authentication. Sansec and Disrex confirmed active compromises affecting Magento Open Source versions 2.4.6-p15 through 2.4.9, and advised merchants to disable GraphQL temporarily while waiting for Adobe’s fix. #StyleSmuggler #MagentoOpenSource #AdobeCommerce #Sansec #Disrex
Keypoints
- StyleSmuggler enables unauthenticated code execution on Magento store servers.
- Sansec saw attacks begin on September 4 and disclosed the flaw early.
- Disrex independently confirmed exploitation on two compromised Magento Open Source stores.
- The implant disguises itself as a kernel thread and persists through cron.
- Temporary advice includes disabling GraphQL and rotating Magento credentials.
Read More: https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html