All CosmicBytez Labs articles tagged #Adobe Commerce, across news, security advisories, how-to guides, and projects.
A max-severity Magento/Adobe Commerce zero-day, StyleSmuggler, has been exploited since September 4 to plant Linux backdoors on live stores.
StyleSmuggler, a Magento zero-day found by Sansec, injects PHP via failed-payment emails to drop a Rust backdoor on live stores.
Sansec found an unpatched Magento/Adobe Commerce 0-day, StyleSmuggler, giving unauthenticated RCE via poisoned templates rendered in failed-payment emails.
Active exploitation of CVE-2026-71362 in Adobe Commerce and Magento is underway, with attackers targeting customer account takeover on e-commerce storefronts.
Mass exploitation is underway against Magento 2 and Adobe Commerce installations using the 'PolyShell' polyglot file upload vulnerability, with attackers...