Critical

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The Hacker News
Actively Exploited

Overview

A new vulnerability in Magento Open Source and Adobe Commerce, identified by the Dutch security firm Sansec and named StyleSmuggler, is currently being exploited by attackers. This flaw allows malicious code to be executed on online store servers without requiring a login, which poses a significant risk to e-commerce platforms. Sansec reported that attacks began on September 4, 2023, just a day before the advisory was published. Online stores using these platforms are at risk of being backdoored, which can lead to unauthorized access and data breaches. Companies running affected systems need to take this threat seriously and implement necessary security measures to protect their customers and data.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Magento Open Source, Adobe Commerce
  • Action Required: Sansec has not specified any patches or updates at this time.
  • Timeline: Disclosed on September 5, 2023

Original Article Summary

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Impact

Magento Open Source, Adobe Commerce

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on September 5, 2023

Remediation

Sansec has not specified any patches or updates at this time. Users should consider implementing security measures such as firewalls, intrusion detection systems, and regular monitoring of their servers for unusual activity to mitigate risks associated with this vulnerability.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Zero-day, Vulnerability, Adobe.

Related Coverage

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

The Hacker News

Cybersecurity researchers have identified a serious vulnerability in the Adobe Acrobat Chrome extension, which has around 314 million users. This flaw, known as HermeticReader and tracked as CVE-2026-48294, could allow malicious websites to access users' WhatsApp Web data without their knowledge. The vulnerability has a CVSS score of 7.4, indicating it poses a significant risk. Adobe has patched this issue, but it raises concerns about the security of extensions and the potential for data breaches. Users of the Adobe Acrobat extension should ensure they have updated to the latest version to protect their data.

Jul 22, 2026

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. One of the most critical is CVE-2026-48282, a path traversal vulnerability in Adobe ColdFusion that could allow attackers to execute arbitrary code. This flaw has a maximum CVSS score of 10.0, indicating its severity. Additionally, vulnerabilities in Joomla and Langflow have also been flagged, though specific details about those flaws were not provided in the article. Organizations using affected products should prioritize applying patches and updates to mitigate these risks, as exploitation in the wild can lead to significant data breaches or system compromises.

Jul 8, 2026

In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops

SecurityWeek

The Department of Homeland Security (DHS) has reported a significant data breach involving one of its databases, although specific details about the extent of the breach or the data compromised have not been disclosed. Meanwhile, Adobe is increasing the frequency of its security updates to better protect users from vulnerabilities, responding to the growing number of cyber threats. In another development, Canadian authorities have successfully disrupted ransomware operations, which is a crucial step in combating the rise of these attacks. Additionally, a data breach at AssuranceAmerica has put the personal information of around 7 million individuals at risk. This series of events illustrates the ongoing challenges organizations face in safeguarding sensitive data and the need for improved security measures across various sectors.

Jul 10, 2026

Hackers Exploit Maximum Severity Adobe ColdFusion Flaw

Infosecurity Magazine

Hackers are taking advantage of a serious vulnerability in Adobe ColdFusion, which has a maximum severity score of 10.0 on the CVSS scale, indicating it poses a significant risk. This flaw allows attackers to execute arbitrary code, potentially compromising systems and accessing sensitive data. Organizations using affected versions of ColdFusion should take immediate action to protect their environments. Adobe has not specified the exact versions impacted, but users of ColdFusion should assume they are at risk if they haven't updated. The fact that this vulnerability is actively being exploited makes it crucial for companies to apply any available patches and review their security measures.

Jul 7, 2026

CISA Adds One Known Exploited Vulnerability to Catalog

All CISA Advisories

CISA has added a new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, specifically CVE-2026-48282, which affects Adobe ColdFusion. This path traversal vulnerability allows attackers to gain unauthorized access and control over affected systems, posing significant risks, particularly to federal agencies. The Binding Operational Directive (BOD) 26-04 emphasizes the need for federal agencies to address high-risk vulnerabilities quickly, while also encouraging all organizations to adopt similar risk-based vulnerability management practices. CISA will continue to update the catalog as new vulnerabilities are identified, and organizations are urged to report any exploited vulnerabilities not currently listed. Rapid remediation is essential to mitigate potential exploitation risks.

Jul 7, 2026

Adobe Patches Critical ColdFusion Vulnerabilities

SecurityWeek

Adobe has released patches to address serious vulnerabilities in ColdFusion that could allow attackers to run arbitrary code or gain elevated privileges. These flaws pose a significant risk to users and organizations that rely on ColdFusion for web applications. If exploited, they could lead to unauthorized access and potential data breaches. It’s crucial for affected users to apply these updates as soon as possible to protect their systems from potential attacks. Adobe's quick response highlights the ongoing need for vigilance in maintaining software security.

Jul 14, 2026