
Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores
Attackers are exploiting an unpatched remote code execution flaw in Adobe Commerce and Magento Open Source to install persistent backdoors on e-commerce sites, Dutch security firm Sansec reported, with the first intrusions observed Sept. 4 and no vendor fix available as of Sept. 6.
Sansec's forensics team, in an advisory, named the flaw StyleSmuggler. No CVE identifier has been assigned. As of Sept. 7, Adobe's Magento security bulletin index listed no September advisory, and the flaw does not appear in CISA's Known Exploited Vulnerabilities catalog, leaving an unknown number of merchants exposed during a window in which working exploit traffic is already circulating.
Magento underpins a ...