Commerce Platforms & DTC
Adobe Commerce

Adobe Commerce max-severity bug comes under active attack

Online stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers. Security firm Sansec is. . .
csoonline.com.au
September 8, 2026
3
Adobe Commerce max-severity bug comes under active attack
WHAT HAPPENED
Online stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers. Security firm Sansec is calling the flaw StyleSmuggler because of the way attackers abused Magento’s Style properties to inject malicious code past existing safeguards. 186 C2 server and waits for commands,” Sansec researchers said in a blogpost, adding that the backdoor had not been weaponized at the time of writing. Magento is the open-source edition of an e-commerce platform used to build and operate online stores. According to Sansec, exploitation began on September 4, with the first confirmed attack recorded at 22:20 UTC.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY