Attacks against Magento stores began on September 4, 2026. Security firm Sansec named the flaw StyleSmuggler. This Magento zero-day gives unauthenticated attackers remote code execution, and criminals are already exploiting it in the wild.
Why this matters
StyleSmuggler hits Magento Open Source and Adobe Commerce. Every current version is affected, including 2.4.9. No official patch exists yet. So online stores face full server takeover with no vendor fix available. Sansec confirmed active attacks and is shipping emergency mitigation.
How the attack works
The Magento zero-day abuses Magento’s template system. According to Sansec, it “injects malicious code into Magento’s template system,” and it uses the styles properties to slip past existing safeguards.
The exploit runs in two stages. First, the attacker poisons PHP code, often by generating a failure report. Then Magento runs that code while it renders a failed payment email. Notably, “the malicious code runs while Magento renders it.” So nobody has to open the message for the attack to succeed.
Exploitation status
Sansec confirms live exploitation. The firm found the campaign on September 4 at 22:40 UTC. It then reproduced the full chain on clean installs within hours. No CVE has been assigned yet, and no public proof-of-concept exploit has been released.
Affected versions
Sansec reproduced the unauthenticated chain on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9. The first known victim ran 2.4.6-p15 with July and August 2026 patches applied. That store showed a clean patch status, yet attackers still got in.
Mitigation steps
Act now, because no patch exists. Sansec advises deploying its Shield product to block exploitation in real time. You should also scan for compromise with a tool like eComscan. If you lack Shield, temporarily disable GraphQL until Adobe ships a fix. Read the full Sansec advisory for indicators of compromise. Adobe’s next security release is due September 8, though its coverage of this bug is unclear.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!