Hackers exploiting Magento and Adobe Commerce zero-day RCE vulnerability

A critical Magento and Adobe Commerce zero-day vulnerability is being actively exploited by hackers to gain remote code execution (RCE) and take control of vulnerable online stores. Security researchers warn that the StyleSmuggler flaw affects current versions, including Magento 2.4.9, and can be exploited without authentication.

Fake Claude Code Installer Spreads Fileless .NET Infostealer via SEO PoisoningFake Claude Code Installer Spreads Fileless .NET Infostealer via SEO Poisoning

Attackers abuse Magento’s GraphQL and email template functionality to inject malicious PHP code and trigger it through the platform’s internal email process. Once successful, attackers can deploy persistent malware, access sensitive store data, and maintain control of compromised servers.

With no official patch available yet, Magento and Adobe Commerce users should urgently strengthen server security, monitor suspicious processes and logs, restrict GraphQL where possible, and apply trusted temporary mitigations until an official security update is released.


Protect your endpoints against malware and exploitation with NPAV Endpoint Security.