An unpatched vulnerability in Magento Open Source and Adobe Commerce platforms is currently being exploited by attackers to execute malicious code on e-commerce servers without the need for login credentials. Sansec, a Dutch e-commerce security firm, disclosed this issue in an advisory on September 5, highlighting the immediate risk to online stores.
Details of the Exploitation
The flaw, identified by Sansec as ‘StyleSmuggler’, first attracted attention on September 4. Despite the potential severity, Adobe had not issued any advisory or patch by September 6. This vulnerability allows attackers to gain code execution rights and create persistent backdoors within affected systems. All current versions, including 2.4.9, are reported as vulnerable.
Sansec’s initial victim was operating version 2.4.6-p15, which had the latest security updates from July and August 2026. The company has not yet confirmed the exact number of compromised stores, nor has it verified the specific affected versions within Adobe Commerce.
Immediate Recommendations and Measures
Sansec advises stores not using its Shield product to disable GraphQL until Adobe provides a temporary fix. This recommendation is crucial since headless and progressive web app storefronts often rely on GraphQL, whereas traditional storefronts might not. Disrex, a company involved in hosting and development for Magento, corroborated Sansec’s findings with independent evidence of exploitation in two stores.
Sansec’s and Disrex’s findings have identified various indicators of this vulnerability, including specific file and process names used by the exploit. They also recommend regular checks for these indicators and suggest using Sansec’s eComscan tool for detection.
Outlook and Future Security Patches
Adobe’s next scheduled security update is on September 8, but it remains unclear whether this update will address the current vulnerability. In the meantime, Disrex and other security experts have provided unofficial mitigations and server settings to help protect against potential exploitation.
For online stores that have already been compromised, immediate actions include preserving evidence, removing malicious cron entries, and securing credentials. Hosting providers, including Nexcess and Liquid Web, are actively reviewing their environments to implement precautionary measures against this exploit.
This situation underlines the critical need for constant vigilance and proactive security measures in e-commerce, especially given the evolving nature of cyber threats.
