This article is produced with scandiweb's eCommerce expertise

Collaborate with our development, PPC, SEO, data & analytics, or customer experience teams to grow your eCommerce business.

Magento and Adobe Commerce Under Attack: scandiweb’s Rapid Response to StyleSmuggler

On Saturday, September 5, 2026, security firm Sansec disclosed StyleSmuggler, an unpatched vulnerability affecting every current version of Magento Open Source and Adobe Commerce, including the latest 2.4.9 release. That’s well over 100,000 stores worldwide. It allowed an unauthenticated attacker, with no login and no user interaction, to run code on a store’s server, access its data, and install a persistent backdoor. For several days, no official Adobe fix existed. 

Update (September 8, 2026): Adobe has released an official fix for StyleSmuggler (CVE-2026-75650) in Security Bulletin APSB26-146. We’re applying it across client stores now. 

This article is an account of how our team responded in the window before that patch when the vulnerability was under active attack, and what any Magento or Adobe Commerce merchant can take from it.

What happened

The disclosure coincided with an active, coordinated wave of attacks, timed for the weekend, when many teams are offline and response times are slowest. Across the stores our team reviewed, we found active exploitation attempts. 

Being up to date was no protection. Sansec reproduced the full attack on clean installations of 2.4.7, 2.4.8, and 2.4.9, and the first confirmed victim was running 2.4.6 with Adobe’s July and August 2026 security updates already installed. With no official fix, we needed to come up with a rapid solution to protect stores that are being actively targeted.

What we did

Our team mobilized outside working hours and worked through client stores individually, alongside protection applied across our hosting environments.

At the platform level, we added infrastructure blocking across our ReadyMage instances, cutting off the known attack path before it reached individual stores. At the store level, we did the following for each project:

  1. Review of server and application logs to establish whether the store had already been targeted
  2. A full backup before any changes were made
  3. Deployment and configuration of a protective shield tuned to this specific attack, applied per store, since this protection works at the project level
  4. Direct verification – our team ran the exploit against the store before and after deploying the shield, confirming it could no longer be executed
  5. Manual testing of the main shopping journeys to confirm the protective changes didn’t disrupt the store
  6. Automated scanning at short intervals, with results reviewed manually by our team
  7. A period of post-deployment monitoring to confirm stability and that the shield was actively blocking the attack.

What merchants should do now

If you run a store on Magento or Adobe Commerce:

  • Apply Adobe’s official hotfix as a priority. It addresses this issue and should be applied immediately. Affected versions run from 2.4.4 through 2.4.9 at the August 2026 patch level and earlier.
  • This vulnerability compromised even fully patched stores, so check for signs of earlier exploitation. Known indicators include unexpected “Payment Transaction Failed Reminder” emails, unfamiliar background processes, new scheduled tasks, and unknown files in the report and temp folders.
  • Remember that patching does not undo a break-in, so a compromise check still matters even after you patch.
  • After any change, test your core shopping journeys, including cart and checkout, to confirm nothing broke.
  • Keep monitoring. More issues like this are likely to surface, and staying protected is ongoing.

What happens next

Adobe’s official hotfix is now available, and we’re applying it across client stores, then reviewing, testing, and confirming each one. Automated scanning and manual review continue alongside it. We’ll update this post if the situation develops further.

If you’re not sure whether your store was exposed before it was protected, or whether it’s fully patched now, we offer a free security check that needs no access to your store. Our Magento engineers review what’s visible externally and email you recommended next steps. Get a free security check or talk to our Magento team now!

For ongoing protection beyond this incident, ReadyMage, our managed Magento and Adobe Commerce hosting, includes malware protection, a firewall, and DDoS defense as standard.

If you enjoyed this post, you may also like