WHAT HAPPENED
SecurityWeek September 8, 2026 2 min read Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports. Dubbed StyleSmuggler , the security defect enables attackers to inject PHP code into Magento’s template system and evade detection by using the ‘styles’ properties. According to Sansec, the attack works in two stages: first, the PHP code is injected by generating a failure report, and then Magento executes the code via a failed payment email. 9, and has been exploited against deployments running the July and August 2026 patches, Sansec says. Successful attacks have been deploying a backdoor against Commerce and Magento stores.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY