Dutch e-commerce security firm Sansec disclosed an unpatched, unauthenticated remote code execution flaw in Magento and Adobe Commerce on September 5, warning that attackers were already using it to backdoor live stores while no fix, advisory, or CVE identifier existed yet.

Sansec calls the bug StyleSmuggler and says it affects every current release, including the newest Magento Open Source 2.4.9, with no authentication required to exploit it. The firm reproduced the attack chain on clean installs of 2.4.7, 2.4.8, and 2.4.9, confirming the flaw is not tied to any single outdated build or missed patch. As of September 6, Adobe’s own security bulletin index for Magento listed nothing past its August 11 update, and Adobe had not assigned a CVE. Sansec said it published its research before finishing its full technical writeup “because stores are being compromised right now.”

The original insight is what this timeline says about the disclosure gap store operators now sit inside. Adobe’s next scheduled security release is September 8, three days after Sansec’s warning and potentially longer after the first live compromises. Until a patch exists, Sansec recommends store operators temporarily disable GraphQL as a stopgap, watch for unexpected bursts of “Payment Transaction Failed Reminder” emails, and scan for unfamiliar background processes and file artifacts consistent with a planted backdoor. Any Magento or Adobe Commerce operator should be running that detection now, not waiting for Adobe’s release date to start looking.

Source: Sansec. Related: CISA Flags Five New Actively Exploited Bugs and PaperCut’s Patched Flaws Are Hitting Schools Now.