AI Weekly Malaysia

Back to items Summaries

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

ID
21889
Status
summarized
Published
06 Sep 2026, 4:14 AM
Fetched
06 Sep 2026, 7:20 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
06 Sep 2026, 7:20 AM
Tags
Audience
developerssaas_startup_founders

What happened

A zero-day dubbed StyleSmuggler is being actively exploited in Magento Open Source and Adobe Commerce since September 4, 2026, allowing unauthenticated remote code execution and persistent backdoor installation. Sansec confirmed all current versions are affected including 2.4.9, and reproduced the full chain on clean installs of 2.4.7, 2.4.8, and 2.4.9. As of September 6, Adobe has released no patch, CVE, or workaround; the only interim mitigation is disabling GraphQL, which breaks headless/PWA storefronts but not classic or Hyvä storefronts.

Why it matters

If you operate or host Magento/Adobe Commerce stores, disable GraphQL immediately if your storefront architecture allows it (classic and Hyvä storefronts can; headless and PWA cannot). Adobe's next scheduled security release is September 8, but it is unknown whether it will cover this bug. Any store running 2.4.6-p15 with the latest August 2026 patches was already compromised, meaning current patch levels offer no protection.

Discussion angle

For Malaysian e-commerce builders: how many local stores run Magento vs. Shopify/WooCommerce, and what's the incident-response plan when a zero-day hits with no patch available—do you have WAF rules ready, and can your storefront survive without GraphQL?

Top