Key Facts
Sansec reports active exploitation of StyleSmuggler, an unauthenticated remote-code-execution chain affecting Magento and Adobe Commerce. Its testing reproduced the chain on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9 installations.
Technical Details
Sansec says the attack injects PHP into Magento’s template system and triggers execution during rendering of a failed-payment email. The research describes follow-on backdoors masquerading as Linux processes and additional web-shell activity on compromised stores.
Impact & Mitigation
Merchants should treat exposed stores as at risk, investigate Sansec’s published indicators, and rotate Magento credentials if suspicious processes are found. Until an official vendor fix is available, Sansec says temporarily disabling GraphQL can reduce exposure.
