
🛡️ **BLUF: Adobe Commerce and Magento Open Source servers under active exploitation — unauthenticated remote code execution via zero-day StyleSmuggler attack. Immediate patching required; monitor for indicators of compromise.**
Published Tuesday, September 08, 2026 at 05:17 AM PT DETAILS Vulnerability: Adobe Commerce and Magento Open Source are affected by a maximum-severity zero-day flaw (CVE-2026-71362) that allows unauthenticated attackers to execute arbitrary code on vulnerable servers. Attack vector: Threat actors abuse Magento’s Style properties to inject malicious code, bypassing existing input validation safeguards. The attack has been nicknamed “StyleSmuggler” by security firm Sansec. ...