Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited

Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited

Posted on September 6, 2026 By CWS

Online retailers using Magento Open Source and Adobe Commerce face an urgent threat from a newly discovered vulnerability. The zero-day exploit, identified by Dutch security firm Sansec as ‘StyleSmuggler’, is being leveraged by attackers to gain full control of e-commerce sites, with no official patch currently available.

Details of the StyleSmuggler Exploit

Sansec revealed the vulnerability on September 5, 2026, noting that it enables remote code execution without requiring authentication. The firm reported that attacks commenced the day before the disclosure. This exploit affects all current versions of Magento and Adobe Commerce, including the latest 2.4.9 release.

Alarmingly, even stores with up-to-date security patches are susceptible. Sansec confirmed this by reproducing the attack on installations of Magento Open Source 2.4.7, 2.4.8, and 2.4.9, showing that the flaw is not linked to outdated versions.

How the Attack Unfolds

The StyleSmuggler exploit unfolds in two stages, exploiting Magento’s template rendering and email systems. Initially, attackers insert malicious PHP code into files created during normal operations via a manipulated GraphQL request. This bypasses existing input sanitization measures.

In the second stage, the execution is triggered when Magento sends a standard ‘Payment Transaction Failed Reminder’ email. The malicious code is executed internally during this process, without any need for the email to be opened.

Defensive Measures and Recommendations

Detection is challenging as the malware disguises itself as a Linux kernel process, evading standard checks. Disrex Group, which conducted an independent analysis, found that the malware interacts with the store’s Redis instance, remaining hidden from network monitors.

Sansec suggests disabling GraphQL for those not using headless storefronts. Meanwhile, unofficial patches have been released by Disrex, ProxiBlue, and Graycore, though these are interim measures rather than permanent fixes. Server-level defenses, such as disabling PHP’s proc_open function, have also proven effective.

As store owners await Adobe’s next security release on September 8, they must rely on these temporary solutions to safeguard their platforms.

Stay informed and protect your online store from potential threats by implementing recommended security measures immediately.

Cyber Security News Tags:Adobe Commerce, Cybersecurity, Disrex, GraphQL, Magento, Malware, online stores, PHP code, RCE, Redis, Sansec, security patches, store protection, Vulnerability, zero-day

Post navigation

Previous Post: Magento and Adobe Commerce Vulnerability Exploited
Next Post: MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Related Posts

New Sneaky 2FA Phishing Kit with BitB Technique Attacking Users to Steal Microsoft Account Credentials New Sneaky 2FA Phishing Kit with BitB Technique Attacking Users to Steal Microsoft Account Credentials Cyber Security News
Venezuela’s Maduro Says Huawei Mate X6 Gift From China is Unhackable by U.S. Spies Venezuela’s Maduro Says Huawei Mate X6 Gift From China is Unhackable by U.S. Spies Cyber Security News
Over 6000 Apache ActiveMQ Servers Risk CVE-2026-34197 Exploit Over 6000 Apache ActiveMQ Servers Risk CVE-2026-34197 Exploit Cyber Security News
Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities Cyber Security News
Threat Actors Weaponize LNK Files With New REMCOS Variant That Bypasses AV Engines Threat Actors Weaponize LNK Files With New REMCOS Variant That Bypasses AV Engines Cyber Security News
American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks
  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited
  • Critical Flaws Fixed in VMware Workstation and Fusion
  • Critical Security Breach: JetBrains Cadence Users Urged to Act

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks
  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited
  • Critical Flaws Fixed in VMware Workstation and Fusion
  • Critical Security Breach: JetBrains Cadence Users Urged to Act

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark