scandiweb
Security alert · StyleSmuggler · Updated September 7, 2026

A critical Magento vulnerability.Our team is on it.

Attackers are exploiting a newly discovered flaw called StyleSmuggler that can give them control of your store and its customer data. scandiweb is checking stores for signs of compromise and applying temporary protection while an official fix is pending.

Patch statusThe latest Sansec advisory reports no official Adobe fix. Adobe’s next security release is scheduled for September 8, but a fix for StyleSmuggler has not been confirmed.

Read the security advisory

What this means for your store

Every current version of Magento Open Source and Adobe Commerce is affected. That is well over 100,000 stores worldwide.

Recent updates may not protect you

The attack has affected a store with Adobe’s July and August security updates installed. Even if your store is up to date, it needs to be checked.

Attackers do not need a login

The vulnerability allows attackers to run malicious code without a customer or administrator account.

Your store and its data could be at risk

A successful attack could allow someone to access sensitive data, modify your store, or install malware.

Protection and investigation both matter

Temporary protection can help block new attacks. Your team also needs to check whether attackers gained access before that protection was in place.

This alert does not mean your store has been compromised. It means you should check your exposure and take protective action now.

Get a free security check

How we’re protecting your store

Our team is treating this as a priority, with three areas of focus:

  1. 1

    Check for signs of compromise

    We inspect your store for malicious files, suspicious background activity, and other known signs of this attack. If we find anything concerning, we’ll explain what we found and the next steps.

  2. 2

    Apply temporary protection

    We apply protective measures against the known attack and check how they affect your store. Once an official fix is available, we’ll review, test, and install it.

  3. 3

    Test the shopping journey

    We manually test key shopping steps, including cart and checkout, and run our core automated tests to check that the protective changes work with your store.

Free initial check · No store access required

Find out what to check next

Share your store address and answer a few questions to get an initial assessment. Our Magento engineers will review your submission, check what is visible externally, and email you recommended next steps.

Step 1 of 3 · Your store

Reviewed by scandiweb’s Magento engineers, including on weekends.

Questions

Common questions

If yours is not here, ask it in the free check or on a call.

Does StyleSmuggler affect Adobe Commerce, or only Magento Open Source?

Both. Adobe Commerce and Magento Open Source share the same core code, and the flaw is in that core. Stores on Adobe Commerce Cloud are affected too.

Which versions are affected?

Every current version, including 2.4.9. The attack has been reproduced on clean 2.4.7, 2.4.8, and 2.4.9 installations, and the first confirmed victim ran 2.4.6 with the latest security patches installed.

My store has all the latest security patches. Am I safe?

No. The first confirmed victim had Adobe’s July and August 2026 security updates installed. There is no patch for this flaw yet, so being up to date does not cover it.

How many stores are affected?

Every store running a current version of Magento Open Source or Adobe Commerce, which is well over 100,000 stores worldwide.

Is there an official fix from Adobe?

Not yet. Adobe has confirmed it is working on a patch but has not given a date. Adobe’s next scheduled security release is September 8, and it is not confirmed to include a fix for StyleSmuggler.

How do I know if my store has been hacked?

From the outside you often cannot tell. Known signs include unexpected “Payment Transaction Failed Reminder” emails, unfamiliar background processes on the server, new scheduled tasks, and unknown files in the report and temp folders. Someone needs to look at the server. The free check on this page is the first step.

What should I do right now?

Three things: have someone check the store for signs of compromise, put temporary protection in place against the known attack, and test cart and checkout afterwards. If you have a Magento partner, ask them today. If not, use the free check on this page or book a call.

Do I need to take my store offline?

Usually not. Temporary protection can be put in place while the store keeps selling. Taking a store offline is a last resort for a store that is confirmed compromised.

What happens once Adobe releases the patch?

The patch has to be reviewed, tested, and installed on your store, and the temporary protection stays in place until that is done. Installing the patch does not remove a backdoor that was planted earlier, so the check for compromise still matters.

Does this affect Hyvä, PWA, or headless stores?

Yes. The flaw sits in the Magento core, not in the theme or frontend. The attack goes through an API that headless and PWA storefronts rely on, so switching that API off is not an option there and protection has to be more targeted.

I am not a scandiweb client. Can you help?

Yes. Start with the free check on this page or book a call. If your store needs work, we agree on the scope with you first.

Talk to our team

Not sure what your store needs?

Speak with our Magento team about your current protection, the checks your store needs, and how to respond to StyleSmuggler.

Managed Magento hosting

Ongoing protection with ReadyMage

ReadyMage is scandiweb’s managed hosting for Magento and Adobe Commerce, with malware protection, a firewall, and DDoS defense built in.

Talk to us about how your hosting can support your store’s security beyond this incident.