Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: adobe-commerce (2 articles)Clear

Unpatched Magento zero-day is being exploited to backdoor online stores

Attackers are actively exploiting an unpatched zero-day in Magento Open Source and Adobe Commerce to run code on stores' servers without logging in, according to e-commerce security firm Sansec, which named it StyleSmuggler. Exploitation began September 4, and every current version is affected, including the latest 2.4.9; Sansec even found a fully patched store already compromised. The attack manipulates a styles field in a GraphQL request to inject PHP into a file the platform generates normally, then installs a persistent backdoor. As of disclosure, Adobe had not issued an advisory, a CVE, or a fix, so exposed stores should be treated as at risk and watched for compromise.

Check
Since there is no patch, review logs for suspicious unauthenticated requests to Magento since September 4, especially style or template processing, and hunt for web shells and new admin accounts.
Affected
Any store on Magento Open Source or Adobe Commerce, including fully patched and latest 2.4.9 installs; an unauthenticated attacker can execute code and install a persistent backdoor, and exploitation is happening now.
Fix
Apply web application firewall rules against anomalous style and template requests, restrict and monitor admin and API endpoints, watch for skimmer injections and backdoors, and apply the vendor fix when it ships.

Adobe Commerce session flaw lets unauthenticated attackers take over customer accounts

Adobe patched a critical flaw in its Commerce and Magento e-commerce platforms that lets an unauthenticated attacker hijack customer accounts, and security firm Sansec reports its web application firewall is already blocking exploitation attempts. Tracked as CVE-2026-71362 and scored 9.1, the incorrect-authorization bug stems from the platform failing to bind a customer identity to an account session, so an attacker with only network access to the public storefront can switch an active session to another customer and read their private data. It needs no account, administrator rights, or user interaction. Adobe ships the fix as isolated patch files, so administrators must be on the latest point release first.

Check
Apply Adobe's August isolated patch for Commerce, Commerce B2B, and Magento after confirming you are on the latest point release for your branch, and treat exploitation traffic as already present.
Affected
Merchants running Adobe Commerce 2.4.4 to 2.4.9 or Magento Open Source 2.4.6 to 2.4.9 (CVE-2026-71362); an unauthenticated visitor can switch into another customer's session and access their account data.
Fix
Patch promptly, put a web application firewall in front of the storefront, review privileged account activity and unexpected configuration changes, and validate extension integrity on internet-facing Commerce instances.