A critical security vulnerability in Magento and Adobe Commerce is under active exploitation, allowing unauthenticated remote code execution (RCE) even on fully patched systems. The flaw, dubbed StyleSmuggler by Dutch security firm Sansec, was first observed in attacks on 4 September 2026. Adobe has acknowledged the issue but has not yet released a patch, CVE identifier, or public advisory as of 7 September 2026. The discovery underscores risks for hosting providers, as the exploit persists outside the web root and evades conventional detection methods.
How the exploit works
StyleSmuggler leverages an injection flaw in Magento’s template system, specifically targeting the "styles" properties to bypass existing safeguards. The attack unfolds in two stages: first, the attacker injects malicious PHP code, often by triggering a failure report. Magento then executes this code while rendering a failed payment email, regardless of whether the email is delivered or opened. Sansec confirmed the exploit works across all current Magento versions, including 2.4.7, 2.4.8, and 2.4.9, and does not require user interaction or session storage modifications.
- First confirmed exploitation: 4 September 2026 at 22:20 UTC
- Affected versions: Magento Open Source 2.4.6-p15, 2.4.7-p2, 2.4.8, 2.4.9
- Mitigation: Disable GraphQL or deploy third-party blocking tools (e.g., Sansec Shield)
- Adobe’s next scheduled security release: 8 September 2026 (no confirmation if it will address this flaw)
- Implant persistence: Cron entries, kernel thread disguises, or self-relaunching processes
The backdoor implant, written in Rust, disguises itself as legitimate system processes such as [kworker/u:8:0], fc-cache, or chronyd. It installs outside the web root—typically in the site user’s home directory or /tmp—and communicates via UDP packets masquerading as NTP traffic. Persistence mechanisms vary, including cron entries written directly to spool files to avoid detection in system logs. Sansec warns that an empty crontab does not guarantee a clean system, as some implants restore themselves within seconds of removal.
Impact on hosting providers
The first two confirmed victims were Magento Open Source stores hosted by Disrex, a provider running its own infrastructure under the RexHosting brand. One store, running Magento 2.4.8 with Sansec’s blocking product enabled, was compromised at 23:10 UTC on 4 September—hours before Sansec released its first blocking rules for the flaw. The second store, on Magento 2.4.7-p2, was breached at 00:55 UTC the following day. Both incidents occurred before mitigation measures were available, highlighting the exploit’s speed and stealth.
For professionals:
Hosting providers should audit authentication logs for repeated crontab: (www-data) AUTH (crontab command not allowed) entries, which indicate failed persistence attempts. Disabling GraphQL is the only confirmed mitigation but may break headless storefronts. Sansec’s indicators of compromise (IOCs) can be used to scan fleets independently of its commercial tools.
Sansec’s advisory notes that session hardening—such as moving sessions to Redis or databases—does not prevent the attack. Additionally, a separate threat actor has been observed dropping web shells into Magento’s product image cache (pub/media), complicating cleanup efforts. The implant’s ability to evade detection by mimicking kernel threads or time-sync processes further complicates incident response for providers managing shared or dedicated environments.
What to watch
Adobe’s next scheduled security release is 8 September 2026, but it remains unclear whether it will include a fix for StyleSmuggler. Until then, hosting providers and merchants must rely on third-party tools or temporary GraphQL disablement. Sansec continues to update its advisory as the investigation progresses, with new indicators and behaviors emerging daily. Providers should monitor for updates and prepare for potential widespread exploitation, given the flaw’s low barrier to entry and high impact.
Automated pipeline · Security
Synthesized from 1 industry feed on 7 Sep 2026. Passed independent editor verification (score 88/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story No recent or in-pipeline article covers the Magento/Adobe Commerce zero-day (StyleSmuggler) exploitation.
- Checking for duplicates — New story pre_write:; No previously published or in-pipeline article covers this Magento zero-day exploit.
- Writing the article — Draft created article_id=517 slug=magento-zero-day-exploited-despite-full-patching
-
Editor review — Approved
- Score: 88/100
- Factual grounding – calendar dates: The draft states 'first observed in attacks on 4 September 2026' and 'first confirmed exploitation: 4 September 2026 at 22:20 UTC'. Source 1 states 'first attacks on September 4' and 'first confirmed exploitation to 22:20 UTC on September 4'. These match exactly, but the draft omits that Source 1 was published on 7 September 2026, so the 4 September date is traceable only to Sansec’s advisory, not an independent source. This is defensible but should be noted as a single-source date.
- Factual grounding – affected versions: The draft lists affected versions as 'Magento Open Source 2.4.6-p15, 2.4.7-p2, 2.4.8, 2.4.9'. Source 1 confirms 2.4.7, 2.4.8, 2.4.9 and the first victim on 2.4.6-p15, but does not explicitly list 2.4.7-p2 as affected. The 2.4.7-p2 reference comes from the second victim’s patch level, but the source does not state it is vulnerable—only that it was breached. This is a minor overreach
- the draft should say 'including' rather than a definitive list.
- Quote integrity – Key facts block: The Key facts block includes 'Mitigation: Disable GraphQL or deploy third-party blocking tools (e.g., Sansec Shield)'. Source 1 states 'Interim mitigation: temporarily disable GraphQL until Adobe ships a fix, for anyone not running Sansec’s own blocking product.' The draft adds 'or deploy third-party blocking tools' and '(e.g., Sansec Shield)', which is a reasonable paraphrase but not a verbatim quote. Since this is a Key facts block, not a blockquote, this is acceptable but should be noted as a minor phrasing deviation.
- Style compliance – Background block: The draft does not include a Background block. While not required, the story could benefit from 2-3 sentences explaining what Magento and Adobe Commerce are for readers unfamiliar with the platform. This is a minor omission.
- Style compliance – headline length: The headline 'Magento zero-day exploited despite full patching' is 48 characters, well under the 90-character limit. This is compliant.
- Generating reader Q&A — Generated 5 items
- Assigning hero image — Rejected library image #358: No candidate sufficiently matches the article topic of a Magento zero-day vulnerability or security exploitation. The provided candidate depicts a generic code snippet (Rust malware), which is too vague and unrelated to Magento, Adobe Commerce, or the specific 'StyleSmuggler' flaw described in the article.
- Assigning hero image — Unsplash unsplash_id=vII7qKAk-9A q=e-commerce website hacking detection picker=The candidate (laptop displaying command prompt) directly aligns with the article's focus on a Magento zero-day vulnerab
- Linking related stories — Linked 1 relations from 449 candidates
- Publishing — Published magento-zero-day-exploited-despite-full-patching
- Mastodon — Posted https://mstdn.social/@hostingpaper/117230795588198082



Discussion · coming soon
Be the first to join the thread when community discussion launches.