Unpatched Magento and Adobe Commerce Zero Day Enables Unauthenticated RCE Since September 4
Sansec disclosed an actively exploited vulnerability, StyleSmuggler, affecting all current Magento and Adobe Commerce versions including Magento Open Source 2.4.9, with confirmed compromises beginning September 4, 2026. The exploit chain requires no authentication, installs a persistent backdoor via Magento's template rendering system, and succeeds even if the triggered email is never delivered. As of September 7, Adobe had published no patch, advisory, CVE identifier, or workaround; available mitigations are third-party emergency measures that block the known exploit chain but do not remove existing infections.