TechNewsReel
Live

StyleSmuggler Zero-Day Hits Magento and Adobe Commerce with Unauthenticated RCE

A critical unpatched vulnerability allows attackers to execute remote code and install persistent backdoors on thousands of e-commerce stores.

TechNewsReel Newsroom · September 5, 2026

Attackers are currently exploiting a critical unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce that allows for full server takeover. The flaw, dubbed "StyleSmuggler," enables unauthenticated remote code execution (RCE), putting thousands of online retailers at immediate risk.

According to research from Sansec, the vulnerability allows attackers to inject malicious PHP code into the platform's template system via "styles" properties. The attack follows a two-stage chain: first, the attacker poisons the system with PHP code, often through failure reports; second, the code is triggered and executed when Magento renders a "Payment Transaction Failed Reminder" email. Exploitation of this flaw began on September 4, 2026, at approximately 22:20 UTC. Sansec noted that they are publishing details early because stores are being compromised in real-time.

A Pattern of Platform Vulnerability

Magento and Adobe Commerce are cornerstone platforms for global e-commerce, but they have been plagued by a recurring pattern of high-impact RCE flaws. StyleSmuggler follows in the footsteps of previous critical vulnerabilities such as PolyShell and SessionReaper. These attacks typically target the platform's API or template systems to bypass authentication and gain server-level access, highlighting a systemic weakness in how the ecosystem handles external inputs within its rendering engines.

Industry Implications

Because the exploit requires no authentication and affects all current versions of the software—including 2.4.7, 2.4.8, and 2.4.9—the potential blast radius is massive. A successful breach allows attackers to install persistent backdoors, providing long-term access for financial theft or espionage. Beyond server control, this level of access enables the theft of sensitive customer data and the manipulation of live orders, which can lead to significant financial loss and regulatory penalties for affected merchants.

Detection and Next Steps

Administrators are urged to monitor their systems for signs of intrusion. Sansec identifies a primary indicator of compromise as a malicious background process disguised as "[kworker/u:8:0]" on the server. As the vulnerability remains unpatched, store owners must remain vigilant for unusual process activity. It remains to be seen when a formal patch will be released to close the StyleSmuggler loophole and secure the template system against similar injection attacks.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.