Magento & Adobe Commerce 0-Day RCE Actively Exploited by Hackers
A critical Magento and Adobe Commerce zero-day vulnerability is being actively exploited by hackers to gain remote code execution (RCE) and take control of vulnerable online stores. Security researchers warn that the StyleSmuggler flaw affects current versions, including Magento 2.4.9, and can be exploited without authentication.


Attackers abuse Magento’s GraphQL and email template functionality to inject malicious PHP code and trigger it through the platform’s internal email process. Once successful, attackers can deploy persistent malware, access sensitive store data, and maintain control of compromised servers.
With no official patch available yet, Magento and Adobe Commerce users should urgently strengthen server security, monitor suspicious processes and logs, restrict GraphQL where possible, and apply trusted temporary mitigations until an official security update is released.
Protect your endpoints against malware and exploitation with NPAV Endpoint Security.
- Other (43)
- Ransomware (182)
- Events and News (28)
- Features (46)
- Security (508)
- Tips (83)
- Google (51)
- Achievements (13)
- Products (39)
- Activation (7)
- Dealers (1)
- Bank Phishing (68)
- Malware Alerts (312)
- Cyber Attack (402)
- Data Backup (17)
- Data Breach (255)
- Phishing (200)
- Securty Tips (10)
- Browser Hijack (34)
- Adware (16)
- Email And Password (94)
- Android Security (102)
- Knoweldgebase (37)
- Botnet (20)
- Updates (13)
- Alert (72)
- Hacking (95)
- Social Media (12)
- vulnerability (137)
- Hacker (120)
- Spyware (18)
- Windows (31)
- Microsoft (51)
- Uber (1)
- YouTube (4)
- Trojan (7)
- Website hacks (22)
- Paytm (1)
- Credit card scam (4)
- Telegram (10)
- RAT (14)
- Bug (5)
- Twitter (3)
- Facebook (15)
- Banking Trojan (19)
- Mozilla (2)
- COVID-19 (5)
- Instagram (6)
- NPAV Announcement (21)
- IoT Security (4)
- Deals and Offers (3)
- Cloud Security (12)
- Offers (6)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- Amazon (5)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (5)
- Cloud malware (7)
- Cloud storage (2)
- Financial fraud (125)
- Impersonation phishing (5)
- DDoS (12)
- Smishing (2)
- Whale (0)
- Whale phishing (8)
- WINRAR (3)
- ZIP (2)
- Fraud Protector (111)
-
Mobile Frauds
(95)
- WhatsApp (26)
- AI (53)
- Windows Patch (0)