StyleSmuggler: The Magento Zero-Day Behind New Store Attacks
A newly discovered flaw in Magento and Adobe Commerce lets attackers break into online stores without a password. They inject malicious code into the store's design files, then run their own programs on your server.
- Report priority
- High
How it works
- Attackers send a specially crafted request to the Magento store's design system.
- This request tricks the store into writing malicious code into its own template files, files that control how the store looks.
- Once the code is hidden there, the attacker can make the store run their own programs on your server.
- This works even if the store has recent security updates, because the flaw hides in the design system rather than the main security patches.
What to do
Check if you run Magento or Adobe Commerce version 2.4.6-p15 or newer. Go to your Magento Admin panel, click System > Status, and look for the Magento version number. If it's 2.4.6-p15 or higher, your store may still be vulnerable. Also, check if your store was recently hacked by looking for unusual activity in your server logs or unexpected files in your store's template folders (like app/design/frontend/).
Sansec is working on a fix, but for now, disable the Magento template system as a temporary stopgap. Contact your Magento hosting provider or developer to apply Sansec's emergency mitigation steps. Monitor your store's logs for suspicious activity. If you suspect an attack, restore your store from a clean backup and change all passwords immediately. For now, check Sansec's official advisory for updates: Sansec StyleSmuggler Advisory.
Technical details
An attacker sends a fake request to a Magento store's design settings, forcing the store to save malicious code into its template files. When visitors load the store, the hidden code runs on the server, letting the attacker take control of the store's backend.
A critical zero-day vulnerability, dubbed StyleSmuggler, affects Magento Open Source versions 2.4.7, 2.4.8, and 2.4.9, allowing unauthenticated attackers to execute arbitrary PHP code on vulnerable stores. The flaw was first observed in active attacks on September 4, 2026, and researchers at Sansec confirmed it bypasses existing safeguards by injecting malicious PHP into Magento's template system. The attack chain abuses the payment transaction failure email feature, even if email delivery fails, to trigger code execution, making it stealthy and difficult to detect.
The vulnerability does not require user interaction (e.g., clicking links or opening attachments) and can compromise stores that appear fully patched, as demonstrated on a 2.4.6-p15 instance with July and August 2026 patches applied. Attackers can use this to install backdoors or maintain persistence. No CVE ID or CVSS score has been assigned.
References
- mozilla.org · mfsa2026-83 vendor advisory
- mozilla.org · mfsa2026-84 vendor advisory
- mozilla.org · mfsa2026-85 vendor advisory
- mozilla.org · mfsa2026-82 vendor advisory
- mozilla.org · advisories vendor advisory
- github.com · advisories vendor advisory
- pulsedive.com · browse Pulsedive
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1108 CERT-FR Advisories
- cert.europa.eu · 2026-010 CERT-EU Advisories
- acn.gov.it · rilevate-vulnerabilita-in-prodotti-mongodb-3 ACN CSIRT Italy
- acn.gov.it · rilevata-vulnerabilita-in-ruby-1 ACN CSIRT Italy
- cyber.gc.ca · google-security-advisory-av26-874 CCCS Canada
- chromereleases.googleblog.com · stable-channel-update-for-desktop.html CCCS Canada
- cyber.gc.ca · hpe-security-advisory-av26-873 CCCS Canada
- support.hpe.com · docDisplay CCCS Canada
- support.hpe.com · securitybulletinlibrary CCCS Canada
- cyber.gc.ca · rockwell-automation-security-advisory-av26-869 CCCS Canada
- rockwellautomation.com · advisory.SD1797.html CCCS Canada
- rockwellautomation.com · advisory.SD1798.html CCCS Canada
- rockwellautomation.com · advisory.SD1794.html CCCS Canada
- rockwellautomation.com · advisory.SD1792.html CCCS Canada
- cyber.gc.ca · mozilla-security-advisory-av26-868 CCCS Canada
- cyber.gc.ca · watchguard-security-advisory-av26-865 CCCS Canada
- psirt.watchguard.com CCCS Canada
- cyber.gc.ca · redis-security-advisory-av26-859 CCCS Canada
- github.com · commit 6d088c3 CCCS Canada
- github.com · releases CCCS Canada
- cyber.gc.ca · nextjs-security-advisory-av26-851 CCCS Canada
- nextjs.org · august-2026-security-release CCCS Canada
- sygnia.co · how-the-safepay-ransomware-group-abused-onedrive-to-steal-data Sygnia
- fortra.com · gunra-ransomware-what-you-need-know Graham Cluley
- blog.nns.ee · project-zomboid-vulns NNS Blog
- openwall.com · 3 Openwall oss-security
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1091 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1106 CERT-FR Advisories
- acn.gov.it · next.js-disponibili-poc-per-2-vulnerabilita ACN CSIRT Italy
- cyber.gc.ca · erlang-security-advisory-av26-870 CCCS Canada
- cyber.gc.ca · dell-security-advisory-av26-863 CCCS Canada
- dell.com · dsa-2026-356-security-update-for-dell-poweredge-server-for-intel-processor-firmware-vulnerability CCCS Canada