Hello,
On 5 September, our partner and security research firm Sansec published details of a previously unknown flaw in Magento and Adobe Commerce, which it has named StyleSmuggler. It allows an unauthenticated attacker to execute code remotely on a store, and Sansec has observed it being used against live stores since 4 September, first seen at 22:40 UTC.
Adobe has not published an advisory, no fix is available and no CVE has been assigned. Adobe's next scheduled security release is 8 September, and it is not yet confirmed whether it will address this issue.
WHICH VERSIONS ARE AFFECTED?
Sansec reproduced the full attack on clean installations of Magento Open Source 2.4.7, 2.4.8 and 2.4.9, and the first store it confirmed compromised was running 2.4.6-p15. Sansec's assessment is that all currently supported versions are affected, including 2.4.9. On that basis we are treating every 2.4.6, 2.4.7, 2.4.8 and 2.4.9 installation as at risk, across Magento Open Source, Adobe Commerce on premises and Adobe Commerce on cloud infrastructure, because all three run the same core code.
Being current on patches does not help here. The first confirmed victim had the July and August 2026 security patches applied and a clean security:patch-status.
Sansec did not test older or end-of-life releases, and we would rather say so than let silence be mistaken for clearance. Versions below 2.4.6, including the 2.4.0 to 2.4.5, 2.3.x and 2.2.x branches, have not been shown to be vulnerable and have equally not been shown to be safe. The template and error-reporting components involved are present in those releases as well, so we are treating them as at risk.
WHAT WEBSCALE IS DOING?
Our security team has been working on this since the advisory was published this morning. We are developing and validating edge-level filtering (WebControl) to reduce exposure ahead of a vendor patch, and we are preparing a compromise check that we will run directly across the applications we host. We will write to you again with the specifics once that work has been through our validation process, and we will contact you individually if we find anything in your environment.
Please treat edge filtering, ours or anyone else's, as a way to reduce exposure and not as a substitute for Adobe's patch.
WHAT WE RECOMMEND YOU DO
- Plan to apply Adobe's fix promptly once it is released and confirmed to address this issue.
Comments
0 comments
Article is closed for comments.