StyleSmuggler zero-day hits Magento and Adobe Commerce stores
Sansec Forensics says StyleSmuggler is an unpatched Magento Open Source and Adobe Commerce zero-day giving unauthenticated remote code execution on current versions, including 2.4.9. Attacks started 4 September 2026. The first victim ran 2.4.6-p15 with July and August 2026 patches and a clean patch-status. There is no Adobe advisory or CVE yet.

Sansec Forensics published a threat-research advisory on 5 September 2026, last updated 6 September at 21:30 UTC, on StyleSmuggler, an unpatched Magento Open Source and Adobe Commerce zero-day that gives unauthenticated remote code execution. All current versions are affected, including 2.4.9.
This is a vendor-adjacent e-commerce research advisory with live exploitation evidence. It is not an Adobe PSIRT bulletin, not a CVE assignment (none exists yet), and not a CISA Known Exploited Vulnerabilities listing.
Attacks started 4 September 2026, with the first confirmed exploitation around 22:20 UTC. Sansec found the campaign at 22:40 UTC the same day. The first victim ran 2.4.6-p15 with the July and August 2026 patches applied and a clean security:patch-status. Sansec later reproduced the full unauthenticated chain on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9.
The chain is two-stage. Attackers inject or poison PHP through styles properties, for example a failure report, then execute it when Magento renders a failed-payment email. A burst of Payment Transaction Failed Reminder messages is a clue. The code runs during render even if the email never delivers.
A GraphQL path is involved (POST /graphql?styles[....]=). Stores that do not run Sansec Shield are told to disable GraphQL until Adobe ships a fix.
Adobe's next scheduled security bulletin is 8 September 2026. Sansec says it is unknown whether that bulletin covers this bug. There was no Adobe advisory or CVE at publication. Sansec is publishing early because stores are being compromised now, and the write-up may change as the investigation continues.
The implant is a Rust backdoor. Early builds disguise as [kworker/u:8:0]. September 6 builds use the name fc-cache (version 2.1.4 observed) and beacon over NTP-shaped UDP to ntp.timesync.to on port 123. C2 also includes 99.84.67.186.
Sansec says it has no indication the backdoor has been used for further commands yet, but treat any implant as a compromise anyway. Shield rules went live the morning of 5 September, eComscan 1.9.7 terminates known processes, and credentials should be rotated if a suspicious process shows up.
Unauthenticated remote code execution on internet-facing platforms is the same class of event as a Cisco Nexus 9000 Silicon One root RCE, SonicWall SMA 1000 zero-days under active attack, a Chrome V8 bug already exploited in the wild, and a WordPress migration plugin takeover.
If you run Magento or Adobe Commerce, disable GraphQL tonight unless a block is already in front of it, hunt for kworker/u:8:0 and fc-cache processes plus failed-payment email bursts, rotate credentials if anything matches, and do not wait for an Adobe CVE that does not exist yet.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free