importantSYS.SOURCE: The Hacker News• 2026-09-06T01:44:47+05:30
Unpatched Magento and Adobe Commerce Zero-Day Exploits Allow Unauthenticated Code Execution and Backdoor Installation
A newly discovered unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce allows attackers to execute arbitrary code and install persistent backdoors without authentication. The flaw, named StyleSmuggler, affects all current versions, with no official patch or CVE identifier released by Adobe as of September 6, 2026.
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5.
Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is
*** END OF TRANSMISSION ***