← Back to Daily Briefing (#ZeroDay)

Critical Unauthenticated RCE "StyleSmuggler" in Adobe Commerce and Magento

Published September 9, 2026

Sansec has identified "StyleSmuggler," a critical zero-day vulnerability enabling unauthenticated remote code execution (RCE) within Adobe Commerce and Magento Open Source. Exploitation, detected in the wild on September 4, 2026, utilizes injection via CSS and style-related parameters to bypass existing security filters. Attackers leverage this vector to deploy sophisticated web shells and persistent backdoors capable of surviving subsequent security patches. This flaw grants complete server-level control, facilitating the theft of customer PII and payment data. Organizations must prioritize immediate file integrity monitoring and credential rotation to mitigate the risk of deep-seated persistence.

  • Vulnerability Mechanics: The StyleSmuggler Vector

    • Exploitation utilizes injection via CSS or style-related parameters to bypass security filters.
    • Enables unauthenticated remote code execution (RCE) without requiring administrative or user privileges.
    • Serves as an entry point for delivering malicious payloads and establishing immediate server-level access.
  • Persistence & Advanced Attacker TTPs

    • Deployment of sophisticated backdoors that remain effective even after subsequent platform patching.
    • Achieves persistence through core file modifications, database manipulation, and the creation of hidden administrative accounts.
    • Exhibits advanced TTPs that represent an evolution from previous Magento-focused "Polyshell" campaigns.
  • Impact & Compliance Risks

    • Complete compromise of the e-commerce environment, resulting in full server-level administrative control.
    • High risk of exfiltration involving sensitive customer PII, session tokens, and encrypted payment data.
    • Critical regulatory exposure regarding PCI-DSS and GDPR due to unauthorized access to sensitive environments.
  • Detection & Mitigation Strategies

    • Perform deep integrity audits of Magento core files to detect unauthorized or malicious modifications.
    • Monitor web server logs for suspicious URL patterns targeting style parameters and anomalous source IPs.
    • Rotate all administrative credentials, API keys, and service tokens immediately upon detection of Indicators of Compromise (IoCs).

Related posts

  1. simplysecuregroup.com — Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability
  2. gbhackers.com — Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
  3. simplysecuregroup.com — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
  4. Security Affairs — StyleSmuggler: The Magento Zero-Day Behind New Store Attacks
  5. Expert In the Cloud — Magento & Adobe Zero‑Day
  6. thehackernews.com — Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
  7. csoonline.com — Adobe Commerce max-severity bug comes under active attack
  8. socprime.com — CVE-2026-75650: Adobe Patches Actively Exploited Magento Zero-Day Used to Deploy Backdoors
  9. sansec.io — StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack
  10. Thehackernews
  11. Greenbone
  12. Mashable
  13. Malwarebytes
  14. Slcyber
  15. Hexnode
  16. Cybersecuritynews
  17. Abijita
  18. Plumrocket

LINK COPIED TO CLIPBOARD