StyleSmuggler: unauthenticated, unpatched Magento/Adobe Commerce zero-day under active exploitation
Sansec disclosed StyleSmuggler, an unauthenticated remote code execution affecting all current Magento Open Source and Adobe Commerce builds including 2.4.9: it smuggles malicious code through a template's `styles` property, then detonates it when Magento auto-sends its own "Payment Transaction Failed Reminder" email, so no admin has to open or click anything. Attacks began September 4 and are ongoing against live stores, and as of publication Adobe has issued no CVE, no advisory, and no patch β an unauthenticated RCE in a major e-commerce platform with zero vendor mitigation to fall back on. If you run Magento or Adobe Commerce, deploy Sansec's Shield WAF rules now and alert on unexpected admin/template writes triggered by payment-failure emails.