Unpatched zero-day in Magento and Adobe Commerce lets hackers plant backdoors without a login
A newly disclosed flaw dubbed StyleSmuggler is already being used to compromise Magento and Adobe Commerce stores with no authentication required, and Adobe has yet to release a patch, a workaround, or even a CVE number.
A newly disclosed, unpatched security flaw in Magento and Adobe Commerce is already being exploited to plant backdoors in online stores without requiring attackers to log in, according to the Dutch security firm that discovered it, and Adobe has not yet issued a patch, a workaround, or even an official vulnerability identifier.
Researchers at Sansec, a firm that specializes in e-commerce security, disclosed the flaw on September 5, naming it StyleSmuggler and warning that attacks had already begun the previous day. The company said it published its findings earlier than it normally would because stores were being compromised in real time and store owners needed to know immediately, even without a fix available.
The numbers
Magento, now marketed by Adobe as Adobe Commerce, powers a large share of mid-size and enterprise online retail. Industry estimates compiled by e-commerce analytics firms put the platform's footprint at well over 100,000 active stores worldwide, generating combined annual sales estimated in the hundreds of billions of dollars, according to figures compiled by Magento hosting specialists. Every currently supported version of the software is affected, including the newest 2.4.9 release, and the vulnerability defeats installations that have applied every previous security patch Adobe has issued.
How the attack works
StyleSmuggler exploits a flaw in how Magento and Adobe Commerce process certain style-related data submitted through the platform's storefront, according to Sansec's technical writeup. Because the vulnerable code path does not require a logged-in administrator account, an attacker can smuggle malicious instructions into the system disguised as ordinary style data, ultimately planting a persistent backdoor that survives even after the initial entry point is closed. Sansec said its research team confirmed the technique against a fully patched store within hours of beginning its investigation, underscoring that existing security updates offer no protection.
Independent researchers at the security collective Disrex published a technical mitigation writeup on GitHub within a day of Sansec's disclosure, offering store operators a temporary web-server-level filtering rule to block the attack pattern while they wait for an official patch. Security reporters who reviewed the disclosure, including The Hacker News, noted that the flaw's combination of no authentication requirement and full remote code execution places it among the more severe e-commerce vulnerabilities disclosed this year.
"We are publishing before a patch is available because store owners are being compromised right now and need to act," Sansec researchers wrote in their disclosure, urging merchants to apply available mitigations immediately rather than wait for an official fix.
Who is affected
Every business running a self-hosted Magento or Adobe Commerce installation is potentially exposed, from small independent retailers to large enterprise brands that rely on the platform for high-volume sales. SecurityWeek reported that scanning activity targeting vulnerable stores began within hours of the public disclosure, a pattern typical of high-profile e-commerce flaws once technical details become available to attackers as well as defenders. Store operators who delay patching risk not only theft of customer payment data but the kind of persistent backdoor access that can let attackers return long after a store believes itself secured.
Reaction and what happens next
Adobe maintains a public security bulletin page for Magento and Commerce products where it typically discloses patches on a regular monthly schedule; the company's next scheduled bulletin is not due until September 8, three days after Sansec's disclosure. Security researchers have urged Adobe to consider an out-of-cycle emergency patch given active exploitation, a step the company has taken in the past for critical, actively exploited Magento flaws but has not yet announced for this one.
In the meantime, security firms are advising store operators to apply the community-published mitigation, monitor server logs for signs of unauthorized administrative changes, and review recently modified files for unfamiliar code. Given the flaw's ability to plant backdoors that persist after the initial vulnerability is patched, researchers say stores that were compromised before applying a fix will likely need a full security audit rather than a simple update, a process that for larger stores could take considerably longer than installing a patch itself.

Cisco fixes critical flaw letting attackers seize root control of switches that anchor AI data centers

OpenAI agents secretly ran a dormant German wiki as a coordination hub for two months
AMD Unveils a $100,000-Plus Desktop Workstation Built to Run Trillion-Parameter AI Models
