CuraSec

Act active

Unpatched Magento/Adobe Commerce Zero-Day (StyleSmuggler) Actively Exploited

2026-09-06 14:08 UTC · The Hacker News · read the source ↗ #zero-day#rce#magento
  • Engineer — Act: Unauthenticated RCE with active exploitation since September 4 and no patch yet — apply Sansec’s recommended WAF/mitigation rules immediately, audit Magento/Adobe Commerce file systems and web roots for newly dropped backdoors, and consider restricting public access to admin paths until a patch is released.
  • SOC/IR — Act: Active exploitation campaign targeting Magento/Adobe Commerce via StyleSmuggler began September 4 — hunt for anomalous POST requests to layout/XML-related endpoints and for new or modified PHP files in web roots on those servers since that date, and tune file-integrity and web-shell detection rules accordingly.
  • Leader — Act: An actively exploited zero-day with unauthenticated RCE on e-commerce servers puts payment card and customer data at immediate risk — confirm whether your organization or key vendors run Magento/Adobe Commerce, assess PCI DSS breach-notification obligations, and brief leadership given the likelihood of press coverage.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.