Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Magento and Adobe Commerce Vulnerability Exploited

Magento and Adobe Commerce Vulnerability Exploited

Posted on September 5, 2026 By CWS

An unpatched vulnerability in Magento Open Source and Adobe Commerce platforms is currently being exploited by attackers to execute malicious code on e-commerce servers without the need for login credentials. Sansec, a Dutch e-commerce security firm, disclosed this issue in an advisory on September 5, highlighting the immediate risk to online stores.

Details of the Exploitation

The flaw, identified by Sansec as ‘StyleSmuggler’, first attracted attention on September 4. Despite the potential severity, Adobe had not issued any advisory or patch by September 6. This vulnerability allows attackers to gain code execution rights and create persistent backdoors within affected systems. All current versions, including 2.4.9, are reported as vulnerable.

Sansec’s initial victim was operating version 2.4.6-p15, which had the latest security updates from July and August 2026. The company has not yet confirmed the exact number of compromised stores, nor has it verified the specific affected versions within Adobe Commerce.

Immediate Recommendations and Measures

Sansec advises stores not using its Shield product to disable GraphQL until Adobe provides a temporary fix. This recommendation is crucial since headless and progressive web app storefronts often rely on GraphQL, whereas traditional storefronts might not. Disrex, a company involved in hosting and development for Magento, corroborated Sansec’s findings with independent evidence of exploitation in two stores.

Sansec’s and Disrex’s findings have identified various indicators of this vulnerability, including specific file and process names used by the exploit. They also recommend regular checks for these indicators and suggest using Sansec’s eComscan tool for detection.

Outlook and Future Security Patches

Adobe’s next scheduled security update is on September 8, but it remains unclear whether this update will address the current vulnerability. In the meantime, Disrex and other security experts have provided unofficial mitigations and server settings to help protect against potential exploitation.

For online stores that have already been compromised, immediate actions include preserving evidence, removing malicious cron entries, and securing credentials. Hosting providers, including Nexcess and Liquid Web, are actively reviewing their environments to implement precautionary measures against this exploit.

This situation underlines the critical need for constant vigilance and proactive security measures in e-commerce, especially given the evolving nature of cyber threats.

The Hacker News Tags:Adobe Commerce, Adobe update, Backdoor, cyber attack, Cybersecurity, Disrex, e-commerce security, GraphQL, Magento, online store security, PHP vulnerability, Sansec, security patch, web security, zero-day vulnerability

Post navigation

Previous Post: Critical Flaws Fixed in VMware Workstation and Fusion
Next Post: Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited

Related Posts

Pegasus Zero-Click Spyware Targeted Serbian Activists Pegasus Zero-Click Spyware Targeted Serbian Activists The Hacker News
Google Launches Android Developer Verification Initiative Google Launches Android Developer Verification Initiative The Hacker News
Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to 2M in Damages Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages The Hacker News
Critical JetBrains TeamCity Flaw Actively Exploited: CISA Critical JetBrains TeamCity Flaw Actively Exploited: CISA The Hacker News
ValleyRAT Malware Concealed in Trusted Adware ValleyRAT Malware Concealed in Trusted Adware The Hacker News
Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited
  • Critical Flaws Fixed in VMware Workstation and Fusion
  • Critical Security Breach: JetBrains Cadence Users Urged to Act
  • Trezor Data Breach at ShipMonk Affects 67,000 U.S. Customers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited
  • Critical Flaws Fixed in VMware Workstation and Fusion
  • Critical Security Breach: JetBrains Cadence Users Urged to Act
  • Trezor Data Breach at ShipMonk Affects 67,000 U.S. Customers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark