Unpatched Magento Vulnerability Exploited in the Wild as StyleSmuggler
Sansec reports active exploitation of zero-day affecting Magento Open Source and Adobe Commerce

Key Takeaways
- An unpatched zero-day vulnerability (StyleSmuggler) in Magento Open Source and Adobe Commerce is under active exploitation.
- Exploitation began on September 4, 2026, and was publicly disclosed on September 5, 2026.
- The flaw allows remote code execution without authentication, potentially leading to server backdoor installation.
Related Security News

Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms report that attackers are exploiting a zero-day vulnerability in Citrix NetScaler to deploy custom web shells and tunneling malware. The exploitation grants root access, enables credential theft, and facilitates lateral movement into internal networks. Citrix has released patches and security advisories addressing CVE-2026-88772.




