Magento Security Alert

StyleSmuggler is live, and being fully patched won't save your Magento store

A critical, actively exploited flaw lets attackers take over Magento and Adobe Commerce stores without logging in. Being on the latest version will not save you. Our £350 fixed-fee emergency investigation confirms whether you have already been hit, and mitigates the threat.

HSL ChairsFactory Direct FlooringIndustvilleDreamsThe EntertainerRhino ProductsLegat OwenWet WednesdaysCarman FriendJaunty Goat86 GroupJPLRoundtowerTowbar ExpressPingyoSMDWildwoodBeat ItZone3Gorgeous ShopWestminster StoneLingerie Outlet StoreMore Handles
£350 Emergency Investigation

Find out if StyleSmuggler has hit your store.

Being on the latest version is no guarantee, and the backdoor is built to slip past the usual scans, so a clean malware report tells you very little. Our fixed-fee investigation settles it: we get an engineer onto your server, check for the specific signs of this attack, tell you plainly whether you have been hit, then lock the vulnerability down.

  • We confirm whether your store has actually been breached, not just guess from the patch level.

  • A server-level forensic check for the specific StyleSmuggler indicators of compromise.

  • We mitigate the vulnerability so you are protected against further attacks.

  • A clear written summary of what we found and exactly what we did.

  • Fast, emergency response from a certified Magento and Adobe Commerce team.

Niko

Request an emergency investigation

£350 fixed fee. Fast response.

For Magento and Adobe Commerce stores. We reply fast and treat this as an emergency.

What is StyleSmuggler?

An unpatched zero-day that hides inside your own Magento files. 

On 5 September 2026, security firm Sansec disclosed StyleSmuggler, an unauthenticated remote code execution flaw in Magento Open Source and Adobe Commerce, with live attacks already underway the day before. It hides malicious code in files Magento writes routinely, then triggers it when Magento builds a payment-failure email. Nobody has to click a thing.

The backdoor poses as a system process, sits outside the web root, repairs itself if removed and needs no external connection, so ordinary malware scans miss it. There is no CVE, no Adobe advisory and no fix. Assume you are exposed until proven otherwise. Our Magento security team can tell you where you stand.

Why This One Is Different

A patch will not save you, and a scan will not find it.

Every current version affected

Every current version affected

Sansec reproduced the full attack chain on Magento 2.4.7, 2.4.8 and the latest 2.4.9, across both Open Source and Adobe Commerce. Earlier 2.4.6 builds are affected too.

No login required

No login required

This is unauthenticated remote code execution. An attacker does not need an account, a password or any interaction from you or your team to run their own code on your server.

No official patch yet

No official patch yet

There is no CVE and no Adobe security advisory at the time of writing. The next scheduled Adobe release may or may not address it. Waiting for a patch is not a safe plan.

Invisible to standard scans

Invisible to standard scans

The backdoor installs outside the web root and masquerades as a system process. Malware scanners and patch-level checks will happily report a clean, up-to-date store.

It repairs itself

It repairs itself

Remove the malicious files and the backdoor can reinstate itself. Half a clean-up is worse than none. It has to be found, understood and fully removed to be gone for good.

Your payment data is the target

Your payment data is the target

Full server control means card-skimming, credential theft and data exposure are all on the table. For a store handling payments, that is a PCI DSS and reputational emergency.

Signs You May Already Be Compromised

The tells are subtle. That is by design.

Payment-failure email bursts

Payment-failure email bursts

Magento's payment transaction failed reminder emails suddenly firing in unusual volumes is a known side effect of the trigger.

Cron jobs you didn't create

Cron jobs you didn't create

Scheduled tasks appearing in your crontab that reference unfamiliar or hidden files are a classic persistence trick.

Hidden files in temp folders

Hidden files in temp folders

Odd files showing up in temporary directories or a user's local share folder, tucked away where nobody looks.

Fake system processes

Fake system processes

Processes dressed up to look like legitimate kernel workers, but running as your web user rather than root.

Strange GraphQL requests

Strange GraphQL requests

Requests to your GraphQL endpoint carrying unfamiliar style or generator parameters buried in your access logs.

A 'clean' store that isn't

A 'clean' store that isn't

Malware scans and patch checks come back green while the backdoor sits outside the web root, completely unseen.

Our Emergency Response

How we investigate and secure your store

Step 01

Preserve & triage

We work with your host to preserve server and access logs before anything is touched, so evidence is not lost. Nothing is deleted until it has been captured.

Step 02

Confirm compromise

We examine the server for the specific indicators of StyleSmuggler: rogue processes, cron persistence, poisoned log and report files, and malicious GraphQL activity.

Step 03

Contain & mitigate

We apply mitigations safely, including locking down the exploited endpoint, without knocking your storefront offline, then stop the attacker in their tracks.

Step 04

Clean & harden

If the store has been breached, we remove the backdoor in full, close the entry point and harden the store so it cannot simply be re-infected.

Step 05

Verify & retest

We re-run the full set of checks to confirm the store is clean, the entry point is closed and your storefront is running normally, so you have proof, not just reassurance.

Step 06

Rotate & report

We rotate admin passwords, API tokens, database and payment credentials an attacker could have captured, then give you a clear written account of what we found and did.

Limely
Niko Moustoukas

Not sure if your Magento store is exposed? Our £350 fixed-fee investigation gives you an answer today.

Trusted With Magento

Stores we build, secure and support on Magento

FAQs

StyleSmuggler: your questions answered

StyleSmuggler is an unauthenticated remote code execution zero-day affecting Magento Open Source and Adobe Commerce. Disclosed by security firm Sansec on 5 September 2026, it lets an attacker run their own code on your store without logging in. Active attacks were already underway before the disclosure went public.

No. This is what makes StyleSmuggler so serious. Sansec reproduced the full attack chain on Magento 2.4.7, 2.4.8 and the latest 2.4.9 release, and one confirmed victim had every available security update applied. As of now there is no CVE, no Adobe advisory and no official patch. Being current does not close the door.

The backdoor is designed to hide. It disguises itself as a legitimate system process, installs outside the web root and can operate without ever calling home, so standard malware scans and patch checks will not spot it. The reliable signals are things like unexpected bursts of Magento payment-failure reminder emails, suspicious cron entries, hidden files in temporary directories, and unusual requests to your GraphQL endpoint in your access logs. Confirming it requires hands-on forensic investigation of the server, which is exactly what we do.

You can reduce your exposure quickly by blocking the GraphQL endpoint at your WAF, CDN or web server, and there is a community mitigation patch doing the rounds. But blocking the entry point does not clean a server that is already compromised, and a rushed change can take your storefront down. We apply mitigations safely and, crucially, verify whether the store has already been breached before assuming a block is enough.

For a fixed fee of £350, we preserve evidence first, then examine the server for indicators of compromise: rogue processes, cron persistence, poisoned log and report files, and malicious GraphQL activity. We confirm whether the store has been breached, then mitigate the vulnerability so you are protected against further attacks. You get a clear written picture of what we found and what we did. If we find you have been breached, any full clean-up, backdoor removal, hardening and credential rotation is quoted separately based on what we uncover.

Yes. We handle Magento and Adobe Commerce stores built by other agencies regularly. For an emergency like this, we work with your hosting provider to preserve server logs and get moving fast, whoever built the site.

Fast. This is a live, actively exploited threat and we treat it as an emergency. Call us on 01244 911 366 or request an emergency investigation and we will get an engineer on your store quickly. Retainer clients go straight to the front of the queue.

What our customers are saying

We're absolutely thrilled with the work Limely have done for us. Taking our website to the next level with Magento 2 was the best thing we ever did, we'll be continuing to work together for the foreseeable!

We are really pleased with our new website and the support and great service Limely have provided during the whole process. Not only are Limely excellent at what they do, but are a friendly, approachable team who put their clients' best interest at the forefront of their work.

The site itself looks great but the way that the whole team were prepared to go the extra mile, including helping me with the brilliantly-written content shows how much they care about their work. Thank-you to the whole team and I look forward to working with you again soon!

I was very pleased with the quality of the websites which Limely built for us. They took a complicated brief and created a bespoke solution which kept everything as simple as possible. The team are a pleasure to work with and I wouldn't hesitate in working with them again for future projects. An excellent web agency.

Our brief was a custom website, with lots of complicated functions along the way, and Limely have smashed it and built us an amazing website. Would 100% recommend to anyone looking to have a new website created, their knowledge, experience and professionalism is the best.

What can I say... the guys at Limely are a dream to work with! Not only have they made our website something to be incredibly proud of but we have made some fab friends in them! Thank you so much for everything!

Paul Hambidge

Paul Hambidge

Factory Direct Flooring

Get eyes on your Magento store now, before an attacker does.

Niko Moustoukas

Tell us about your store and your hosting setup. For a £350 fixed fee we will move fast to confirm whether you have been hit by StyleSmuggler, mitigate the vulnerability and get you back to safe ground.

Get started

What our customers are saying

We're absolutely thrilled with the work Limely have done for us. Taking our website to the next level with Magento 2 was the best thing we ever did, we'll be continuing to work together for the foreseeable!

We are really pleased with our new website and the support and great service Limely have provided during the whole process. Not only are Limely excellent at what they do, but are a friendly, approachable team who put their clients' best interest at the forefront of their work.

The site itself looks great but the way that the whole team were prepared to go the extra mile, including helping me with the brilliantly-written content shows how much they care about their work. Thank-you to the whole team and I look forward to working with you again soon!

I was very pleased with the quality of the websites which Limely built for us. They took a complicated brief and created a bespoke solution which kept everything as simple as possible. The team are a pleasure to work with and I wouldn't hesitate in working with them again for future projects. An excellent web agency.

Our brief was a custom website, with lots of complicated functions along the way, and Limely have smashed it and built us an amazing website. Would 100% recommend to anyone looking to have a new website created, their knowledge, experience and professionalism is the best.

What can I say... the guys at Limely are a dream to work with! Not only have they made our website something to be incredibly proud of but we have made some fab friends in them! Thank you so much for everything!

Paul Hambidge

Paul Hambidge

Factory Direct Flooring

Ready to start your success journey?

Niko Moustoukas

Get in touch today to book a meeting

Get started