Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageVulnerabilities Desk
Vulnerabilities

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

A pre-auth zero-day in Magento / Adobe Commerce is being weaponised to plant backdoors on live storefronts — no patch exists yet, making WAF-based virtual patching the only immediate shield for affected retailers.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5.

Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

Editorial Analysis

Framed for the DevSecOps Engineer desk

Why it matters

Unpatched RCE in a popular open-source commerce stack highlights the need for runtime protection layers when vendor patches lag.

What to do

Enable RASP or virtual-patching on commerce application servers and restrict outbound network access to known-good destinations.

Board brief

An unpatched zero-day is actively compromising online stores; mitigation costs are low but delay increases breach-notification risk under GDPR.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Vulnerabilities Desk