Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Summary

Attackers are actively exploiting a newly discovered, unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce. This flaw, dubbed StyleSmuggler by its discoverer Sansec, allows threat actors to execute malicious code on e-commerce servers without requiring any prior login credentials. The exploitation of this vulnerability began on September 4th, shortly before the advisory was published on September 5th.

IFF Assessment

FOE

This is bad news for defenders as an unpatched zero-day vulnerability is being actively exploited in the wild, allowing attackers to compromise e-commerce platforms.

Severity

9.8 Critical (AI Estimated)

The vulnerability allows for unauthenticated remote code execution on e-commerce servers, indicating a critical severity. The exploitability is high due to lack of authentication and significant impact on confidentiality, integrity, and availability.

Defender Context

Defenders managing Magento or Adobe Commerce installations must prioritize patching this vulnerability immediately to prevent further compromises. It highlights the critical need for rapid response to zero-day exploits targeting widely used e-commerce platforms.

Read Full Story →