StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack
released on 2026-09-05 @ 08:33:07 PM
StyleSmuggler is an unpatched zero-day vulnerability affecting all current versions of Magento and Adobe Commerce, including version 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecting malicious PHP code through the styles properties to evade safeguards, then executing it via failed payment email templates. The vulnerability exploits Magento's GraphQL endpoint and template system. Attackers deploy backdoors disguised as legitimate system processes, establish command and control through multiple domains using WebSocket over TLS and custom NTP-shaped traffic. Affected merchants should deploy protective measures, scan for compromise indicators including suspicious background processes, and consider temporarily disabling GraphQL until an official patch is released.