Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

September 6, 2026 1 Min Read 0
Threat Intelligence Brief

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Source: thehackernews.com
Threat Risk: Critical
Victim: Enterprise Organizations & Affected Platforms
Incident: Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Impact: Unauthenticated remote exploitation, data theft, or compromise of exposed infrastructure.
Attacker: Active Threat Actors / Exploitation Groups
Analysis: Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5.

Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. “Sansec is…
Recommendations: Apply emergency vendor updates, monitor network perimeters, and isolate vulnerable endpoints.; Review authentication logs for anomalous remote commands.
Source: The Hacker News

Editorial note: this post summarizes high-priority intelligence and links to primary telemetry.
View Primary Telemetry →

Leave a Reply

Your email address will not be published. Required fields are marked *