# Unpatched Magento flaw is being exploited to backdoor online stores

_Thursday, September 3, 2026 at 8:00 PM EDT · Security, Products · Latest · Tier 1 — Major_

![Unpatched Magento flaw is being exploited to backdoor online stores — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjghsT_skiIfdOHK2B0WWDfWnSK0G5Ih7BqsX98tKrY4TH7I77oLEmnldtVHuUMEQaIiZZBSPJGI2t8Me7h9kDtE4YGZ9-5NypnAu2-yFFrXsWYkR6OJPlbqkZDEHBAXCmRjWm6Mk4h0Ni48JT0nrDWMYygztjoi4HuHPbe2y-2jreFVkzrxO8r4IhHIEU/s1700-nu-rw-lo-l85-e365/adobe-exploit.jpg)

Attackers began exploiting an unpatched vulnerability in Magento Open Source and Adobe Commerce on September 4, according to Sansec.

The company said the flaw, which it calls StyleSmuggler, allows unauthenticated code execution on a store server and can install a persistent backdoor. Sansec said current Magento versions are affected and that it reproduced the chain on clean 2.4.7, 2.4.8 and 2.4.9 installations. Disrex separately reported responding to two compromised stores, but Adobe had not issued an advisory, CVE, patch or workaround.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html)

---
Canonical: https://techandbusiness.org/newswire/gcOT7RvFzWRdDzLBLMAIoM
Retrieved: 2026-09-05T23:46:33.178Z
Publisher: Tech & Business (techandbusiness.org)
