Attackers are actively exploiting an unpatched zero-day in Magento Open Source and Adobe Commerce to run code on stores' servers without logging in, according to e-commerce security firm Sansec, which named it StyleSmuggler. Exploitation began September 4, and every current version is affected, including the latest 2.4.9; Sansec even found a fully patched store already compromised. The attack manipulates a styles field in a GraphQL request to inject PHP into a file the platform generates normally, then installs a persistent backdoor. As of disclosure, Adobe had not issued an advisory, a CVE, or a fix, so exposed stores should be treated as at risk and watched for compromise.
Adobe patched a critical flaw in its Commerce and Magento e-commerce platforms that lets an unauthenticated attacker hijack customer accounts, and security firm Sansec reports its web application firewall is already blocking exploitation attempts. Tracked as CVE-2026-71362 and scored 9.1, the incorrect-authorization bug stems from the platform failing to bind a customer identity to an account session, so an attacker with only network access to the public storefront can switch an active session to another customer and read their private data. It needs no account, administrator rights, or user interaction. Adobe ships the fix as isolated patch files, so administrators must be on the latest point release first.