Palo Alto Networks Unit 42 reported that an unpatched, unauthenticated RCE zero-day vulnerability named 'StyleSmuggler' is being exploited to compromise e-commerce sites running Magento Open Source and Adobe Commerce.
Public source
Publisher name
Public post
🚨 Unpatched 'StyleSmuggler' RCE Flaw Hits Magento & Adobe Commerce An unpatched, unauthenticated RCE zero-day vulnerability named 'StyleSmuggler' is being actively expl…
Company
Palo Alto Networks Unit 42
Unit 42 Threat Intelligence & Incident Response. Intelligence Driven. Response Ready.
- Industry
- Computer and Network Security
- Location
- SANTA CLARA, US
- Company size
- 501–1,000 employees
About Palo Alto Networks Unit 42
Palo Alto Networks Unit 42 brings together world-renowned threat researchers with an elite team of incident responders and security consultants to create an intelligence-driven, response-ready organization passionate about helping customers more proactively manage cyber risk. With a deeply rooted reputation for delivering world-class threat intelligence, Unit 42 provides industry-leading incident response and cyber risk management services to security leaders around the globe.
See moreLatest activity
Latest activity from Palo Alto Networks Unit 42
23 signals
Research & Knowledge
Palo Alto Networks Unit 42 analyzed activity cluster CL-CRI-1163, where adversaries targeted the Brazilian financial sector by deploying custom SOCKS5 proxy tools alongside open directories filled with AI-generated python scripts.
Research & Knowledge
Palo Alto Networks Unit 42 analyzed activity cluster CL-CRI-1131, where adversaries integrated commercial AI models into operational workflows and used self-hosted NextChat instances to troubleshoot data collection errors in real time.
Products & Services
Palo Alto Networks Unit 42 is urging on-premises customers to apply an emergency hotfix for its N-central RMM platform to address a critical, actively exploited zero-day vulnerability CVE-2026-86218.
Discover more
Similar signals
Similar public activity from other companies.
Products & Services
Wagento Commerce
Wagento Commerce published a critical security alert for Magento and Adobe Commerce merchants and engineering teams regarding a zero-day Remote Code Execution (RCE) vulnerability dubbed StyleSmuggler.
Products & Services
Hypernode
Hypernode reported that Adobe Commerce and Magento Open Source stores received the official fix APSB26-146 for the StyleSmuggler zero-day vulnerability.
Products & Services
SOCRadar® Extended Threat Intelligence
Socradar® Extended Threat Intelligence confirmed that stores fully patched with July and August 2026 updates are affected by the StyleSmuggler zero-day vulnerability.
Products & Services
Mage-OS
Mage-OS is affected by a Magento zero-day on September 5, which is being exploited by StyleSmuggler.
Security Corporation
Tenable