Summary
- Sansec says its StyleSmuggler chain gives unauthenticated attackers remote code execution on current Magento and Adobe Commerce releases.
- The company recorded its first confirmed exploitation late on 4 September and reproduced the chain on clean installations.
- Active attacks are occurring before an official Adobe fix is available.
Attackers are exploiting a previously unknown vulnerability chain affecting Adobe Commerce and Magento Open Source, with security researchers reporting unauthenticated remote code execution against live online stores.
E-commerce security company Sansec disclosed the issue on 5 September after recording its first confirmed exploitation late on 4 September. It has named the technique StyleSmuggler and says all current Magento versions are affected, including 2.4.9.
The researchers reproduced the complete unauthenticated chain on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9 installations. The first compromised store examined by Sansec was running 2.4.6-p15 with the July and August 2026 security patches applied.
The attack abuses Magento’s template system and its handling of style properties. Sansec describes a two-stage process in which malicious PHP code is first introduced into a file and subsequently executed when Magento processes a failed-payment email.
The operational consequence is a trust-boundary failure between unauthenticated web input and server-side code execution. A remote attacker can potentially convert an application request into execution on the host running the commerce platform.
Sansec said an official Adobe fix was not available when it published its analysis. Adobe’s next scheduled security release was due on 8 September, but Sansec said it did not know whether that release would address StyleSmuggler.
That leaves merchants and service providers managing an active-exploitation interval in which normal patch-management sequencing does not apply. There is no vendor update yet to test and deploy, while attacks have already been observed.
The exposure is particularly uncomfortable in e-commerce environments. Magento and Adobe Commerce commonly sit close to customer information, payment workflows, administrative accounts, marketing platforms, and external integrations. Server-level access can consequently create risks extending beyond website availability.
Sansec said successful attacks install a backdoor process that connects to command-and-control infrastructure and waits for instructions. At publication, the company said it had not seen evidence that the observed backdoor had subsequently been used for additional malicious activity.
That distinction should remain intact. The existence of a backdoor establishes persistence following successful exploitation; it does not establish what every compromised system was subsequently used for.
Historic attacks against commerce platforms nevertheless show why remediation cannot end with installation of a later patch. If an attacker gained server access before the vulnerability was closed, updating the application does not automatically remove an implant or secondary persistence mechanism introduced earlier.
The incident also exposes a recurring supply chain problem for organisations relying on widely deployed web platforms. A single platform vulnerability can create simultaneous exposure across large numbers of independently operated businesses, while attackers can probe the internet faster than individual merchants can investigate affected systems.
Responsibility can be divided further where hosting, development, maintenance, and security are split between merchants, agencies, managed providers, and software vendors. During an unpatched zero-day, uncertainty over who owns emergency mitigation can become part of the operational risk.
Sansec says it disclosed the vulnerability early because live stores were already being compromised. Adobe’s response is now the central dependency: when an official fix becomes available, which versions it covers, and how much exploitation occurs before affected stores can move onto a corrected release.





