StyleSmuggler runs unauthenticated code on every current version of Magento and Adobe Commerce
Sansec documents StyleSmuggler, a Magento and Adobe Commerce zero-day exploited since September 4, 2026 that runs code without authentication through the template engine and installs a persistent backdoor. Adobe has published no CVE and no patch yet: disable GraphQL on your stores while waiting for the September 8 bulletin.