Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- ID
- 21889
- Status
- summarized
- Published
- 06 Sep 2026, 4:14 AM
- Fetched
- 06 Sep 2026, 7:20 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 06 Sep 2026, 7:20 AM
- Tags
- Audience
- developerssaas_startup_founders
What happened
A zero-day dubbed StyleSmuggler is being actively exploited in Magento Open Source and Adobe Commerce since September 4, 2026, allowing unauthenticated remote code execution and persistent backdoor installation. Sansec confirmed all current versions are affected including 2.4.9, and reproduced the full chain on clean installs of 2.4.7, 2.4.8, and 2.4.9. As of September 6, Adobe has released no patch, CVE, or workaround; the only interim mitigation is disabling GraphQL, which breaks headless/PWA storefronts but not classic or Hyvä storefronts.
Why it matters
If you operate or host Magento/Adobe Commerce stores, disable GraphQL immediately if your storefront architecture allows it (classic and Hyvä storefronts can; headless and PWA cannot). Adobe's next scheduled security release is September 8, but it is unknown whether it will cover this bug. Any store running 2.4.6-p15 with the latest August 2026 patches was already compromised, meaning current patch levels offer no protection.
Discussion angle
For Malaysian e-commerce builders: how many local stores run Magento vs. Shopify/WooCommerce, and what's the incident-response plan when a zero-day hits with no patch available—do you have WAF rules ready, and can your storefront survive without GraphQL?