Wire · regulatory
StyleSmuggler zero-day in Magento and Adobe Commerce actively exploited
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 7 September 2026 · Fusion42 review
A zero-day vulnerability named StyleSmuggler in Magento and Adobe Commerce has been actively exploited since early September, allowing attackers to execute malicious code and establish persistent backdoors without authentication. No patch has yet been released, and operators are advised to disable GraphQL temporarily and search for compromise indicators.
This Wire brief sits within Fusion42's coverage of E-commerce and Cybersecurity, and 2 sources have reported it between 5 Sep 2026 and 7 Sep 2026.
◆ ◆ The Wire takeaway
You face a rising threat from unpatched Magento and Adobe Commerce exploits that target GraphQL and server code. Immediate steps to disable GraphQL and hunt for backdoor indicators are essential to protect your e-commerce platform now.
◆ Coverage
2 sources · first reported 5 Sep 2026 · latest 7 Sep 2026
◆ Related on Wire
◆ Topics