Back to News
Cybersecurity

Critical Zero-Day Vulnerability in Magento and Adobe Commerce Exploited for Malicious Attacks

A new zero-day vulnerability in Magento and Adobe Commerce is being actively exploited, posing significant risks to online retailers.

A recently identified zero-day vulnerability, dubbed StyleSmuggler, in Magento Open Source and Adobe Commerce is being actively exploited by attackers to execute malicious code on the servers of online stores without requiring authentication. Discovered by the Dutch e-commerce security firm Sansec, the exploitation of this flaw began on September 4, shortly before the advisory was published on September 5. The vulnerability poses a critical threat, as it allows attackers to compromise online retail environments, potentially leading to data breaches and financial losses.

For businesses relying on Magento or Adobe Commerce platforms, the implications are dire. Immediate action is required to assess their systems for potential vulnerabilities and implement security measures to mitigate the risk of exploitation. This situation underscores the importance of timely software updates and vulnerability management, particularly as cyber threats continue to evolve. Given the increasing sophistication of cyberattacks, this vulnerability highlights the essential need for robust cybersecurity strategies and proactive monitoring to safeguard sensitive customer data and maintain trust in online commerce. The incident serves as a reminder that unpatched software can quickly become a vector for significant security breaches, further emphasizing the critical intersection of cybersecurity and e-commerce operations.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html)*