Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
criticalDetails
A new, unpatched zero-day vulnerability, named 'StyleSmuggler', is being actively exploited in Magento Open Source and Adobe Commerce. The flaw allows unauthenticated attackers to execute arbitrary code on a server, enabling them to backdoor online stores. Attacks have been observed in the wild since September 4th.
Affected Systems
Magento Open Source, Adobe Commerce (specific versions not detailed in reporting).
Potential Impact
Complete compromise of e-commerce platforms, leading to data theft (customer data, payment information), installation of backdoors, and potential financial fraud.
Mitigations
As no official patch is available, organizations should immediately apply compensating controls. Monitor for indicators of compromise provided by security firms like Sansec and restrict access to administrative endpoints. Prepare to apply the official patch as soon as it is released by Adobe.