Back to advisories

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

A zero-day vulnerability called StyleSmuggler in Magento Open Source and Adobe Commerce is being actively exploited to achieve unauthenticated remote code execution and install persistent backdoors. All current versions are affected. Threat actors began attacks before public disclosure, meaning your Magento/Commerce instances may already be compromised.

CRITICALAdvisorySep 05, 2026
Action required
Immediately inventory all Magento Open Source and Adobe Commerce instances in your environment. Scan web server logs for suspicious POST requests and template injection payloads. Isolate any affected systems and search for webshells, cron jobs, and database modifications consistent with backdoor installation.
Affected products
Magento Open SourceAdobe CommerceSansecAdobeGraphQL