Magento Zero-Day: Unpatched Adobe Commerce RCE Is Backdooring Online Stores
On 4 September 2026, attackers began exploiting an unpatched remote code execution flaw in Magento Open Source and Adobe Commerce. Dutch e-commerce security firm Sansec disclosed the issue on 5 September and named it StyleSmuggler. The company said it published early because stores were being compromised in real time.