CRITICAL: Magento and Adobe Commerce Zero-Day Exploited With No Patch Available
Attackers are actively exploiting an unpatched remote code execution flaw in Magento Open Source and Adobe Commerce that Sansec has named StyleSmuggler. Every current version is affected including 2.4.9, exploitation began on September 4, and Adobe has not published a CVE, an advisory, or a fix. The chain ends in a persistent Rust backdoor disguised as a kernel thread.