StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack
Reported 07 Sep 2026 by otx · Severity: medium
An unpatched zero-day vulnerability dubbed StyleSmuggler affects all current versions of Magento and Adobe Commerce, including 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecting mal