
StyleSmuggler poisoned the failed-payment mail
Sansec says an unauthenticated Magento and Adobe Commerce zero-day has been under active attack since 4 September 2026. All current versions are in scope, including 2.4.9. As of Sansec’s 6 September update, Adobe had not issued an official fix.











