Active Zero-Day Attacks Hit Magento and Adobe Commerce Stores, No Patch Yet
Security firm Sansec has revealed that attackers are actively exploiting a new, unpatched vulnerability in Magento Open Source and Adobe Commerce, allowing them to run malicious code on store servers without any login. The flaw, named StyleSmuggler, has been exploited since September 4, and Sansec chose to publish its findings early because stores are being compromised right now. As of September 6, Adobe has not released an advisory, patch, workaround, or vulnerability identifier for the issue.
Sansec confirmed the unauthenticated attack chain works against current Magento versions, including 2.4.9, and reproduced it on clean installs of 2.4.7, 2.4.8, and 2.4.9. Worryingly, the first known victim was running a fully patched version with Adobe's latest available security updates, suggesting the flaw affects even up-to-date stores. A successful attack grants attackers server-level code execution and installs a persistent backdoor, giving them ongoing access even after the initial breach.
Hosting company Disrex Group independently confirmed exploitation, reporting it responded to two compromised stores and a third that was targeted but not breached on September 5. Until Adobe issues a fix, Sansec is advising store owners who don't use its Shield product to disable GraphQL, a feature required mainly by headless and progressive web app storefronts, but not typically needed by classic or Hyvä storefronts. Adobe's next scheduled security release is September 8, though it is unclear if it will address this issue.