<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores]]></title><description><![CDATA[<p dir="auto">Attackers are actively exploiting an unpatched vulnerability in Magento Open Source and Adobe Commerce, allowing them to execute arbitrary code on affected servers without requiring authentication. Dutch e-commerce security firm Sansec, which discovered the flaw and dubbed it <em>StyleSmuggler</em>, issued an advisory on September 5 after observing the first attacks on September 4.</p>
<p dir="auto">The zero-day enables remote code execution (RCE) by smuggling malicious payloads through what Sansec describes as a previously unknown attack vector. This allows threat actors to backdoor online stores and potentially steal payment data or compromise the entire infrastructure underlying the e-commerce platform.</p>
<ul>
<li>Both Adobe Commerce and Magento Open Source installations are at risk.</li>
<li>No official patch was available at the time of Sansec's disclosure, leaving stores vulnerable to active exploitation.</li>
<li>Sansec has stated it is publishing early indicators of compromise and mitigation guidance for merchants.</li>
</ul>
<p dir="auto">Given the lack of a vendor-supplied fix, administrators are urged to audit their systems for signs of intrusion immediately and apply any available workarounds provided by security researchers. The exact technical mechanics of the vulnerability have not been fully disclosed to prevent further abuse while the zero-day remains open.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your team already taking steps to trace unauthorized file changes or review server logs for the specific attack patterns Sansec mentioned, or are you waiting for an official patch before intervening?</p>
]]></description><link>https://xploitlk.com/topic/230/unpatched-magento-and-adobe-commerce-zero-day-exploited-to-backdoor-online-stores</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:28:21 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/230.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 05 Sep 2026 22:30:21 GMT</pubDate><ttl>60</ttl></channel></rss>