Security researchers disclosed a critical, actively exploited zero-day vulnerability impacting Magento Open Source and Adobe Commerce. The flaw, called StyleSmuggler, permits unauthenticated remote code execution that attackers used to install persistent backdoors and web shells on store servers. Public reporting ties the exploitation to a mass campaign that compromised more than 3,800 stores.
Sansec (the Dutch e-commerce security firm that discovered the issue) published details after seeing active attacks. The exploit chain can be triggered without authenticating to the application, so attackers could execute arbitrary code on vulnerable installations. Once code execution is achieved, attackers drop backdoors (including PHP web shells and other persistent implants) to maintain access and facilitate further malicious actions such as data theft or payment card skimming.
Reports place the start of observed attacks in early September 2026. The campaign rapidly expanded, with the number of affected storefronts reported at more than 3,800. Adobe subsequently issued patches to remediate the vulnerability. Third-party reporting describes follow-on activity that includes deployment of Linux and Rust-based backdoors in some incidents.
Why this matters to store operators
Magento and Adobe Commerce power many online retailers. A zero-click, unauthenticated remote code execution vulnerability means a successful exploit can give an attacker full control over the web application and, by extension, its hosting environment. For e-commerce platforms, that permits payment-card theft, skimming of checkout pages, tampering with product pages, and persistent access that can survive basic remediation.
Immediate steps for affected or potentially affected stores
- Treat any store running an affected Magento or Adobe Commerce version as potentially compromised.
- Apply the official Adobe security updates or patches as provided. If patches were unavailable at the time of initial disclosure, deploy them immediately now that Adobe has released fixes.
- Conduct a thorough hunt for backdoors and web shells. Look for unusual PHP files, scheduled tasks, new administrative users, and outbound connections to unknown hosts.
- Rotate credentials and revoke compromised secrets, API keys, and any stored payment credentials where appropriate.
- Engage incident response or forensic specialists if persistent implants are identified or if you lack internal capability.
After containment and remediation, review patching practices and detection controls for web application threats. Implement file integrity monitoring, restrict code deployment paths, and harden server access. Consider external scanning and continuous monitoring tailored to e-commerce platforms to accelerate detection of similar exploitation attempts.
A severe, unauthenticated remote code execution vulnerability in Magento and Adobe Commerce was actively exploited to install backdoors on thousands of stores. If you run either platform, assume risk, apply Adobe's patches, and perform incident response and forensic checks to find and remove persistent implants.