StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack

Reported 05 Sep 2026 by otx · Severity: medium

StyleSmuggler is an unpatched zero-day vulnerability affecting all current versions of Magento and Adobe Commerce, including version 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecti