Magento Open Source and Adobe Commerce StyleSmuggler zero-day actively exploited security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Attackers are actively exploiting StyleSmuggler in Magento Open Source and Adobe Commerce, enabling unauthenticated code execution and persistent backdoors on store servers.
Related Happenings
GorgonAgora fake .shop card-skimming campaign
Campaign
H score84
First: 05.06.2026 11:38
Last: 05.06.2026 11:38
Sources 1
About this happening:
The GorgonAgora campaign is using 5,714 fake .shop storefronts to steal payment data, widening card-theft risk across brand-impersonation checkout pages. The operation has...
GorgonAgora fake .shop card-skimming campaign
CampaignAbout this happening: The GorgonAgora campaign is using 5,714 fake .shop storefronts to steal payment data, widening card-theft risk across brand-impersonation checkout pages. The operation has...
Funnel Builder plugin WordPress arbitrary JavaScript injection actively exploited security flaw
Vulnerability
H score72
First: 16.05.2026 18:20
Last: 16.05.2026 18:20
Sources 1
About this happening:
Funnel Builder for WordPress is under active exploitation for arbitrary JavaScript injection into WooCommerce checkout pages, creating payment-skimming risk across...
Funnel Builder plugin WordPress arbitrary JavaScript injection actively exploited security flaw
VulnerabilityAbout this happening: Funnel Builder for WordPress is under active exploitation for arbitrary JavaScript injection into WooCommerce checkout pages, creating payment-skimming risk across...
Funnel Builder WordPress plugin unauthenticated checkout script injection actively exploited security flaw
Vulnerability
H score69
First: 15.05.2026 22:30
Last: 15.05.2026 22:30
Sources 1
About this happening:
Funnel Builder for WordPress has an actively exploited unauthenticated script-injection flaw that can compromise WooCommerce checkout pages and steal payment data. The...
Funnel Builder WordPress plugin unauthenticated checkout script injection actively exploited security flaw
VulnerabilityAbout this happening: Funnel Builder for WordPress has an actively exploited unauthenticated script-injection flaw that can compromise WooCommerce checkout pages and steal payment data. The...
Adobe Reader zero-day exploited via malicious PDFs security flaw
Vulnerability
H score38
First: 09.04.2026 12:22
Last: 09.04.2026 12:22
Sources 1
About this happening:
Adobe Reader is facing an actively exploited zero-day delivered through malicious PDF documents and observed since at least December. The flaw works on the lates...
Adobe Reader zero-day exploited via malicious PDFs security flaw
VulnerabilityAbout this happening: Adobe Reader is facing an actively exploited zero-day delivered through malicious PDF documents and observed since at least December. The flaw works on the lates...
Latest development: 13.04.2026 18:37
Adobe released an emergency security update for Acrobat Reader to fix CVE-2026-34621 after zero-day exploitation in malicious PDF files. The bulletin says Acrobat DC versions 26.001.21367 and earlier, Acrobat Reader DC versions 26.001.21367 and earlier, and Acrobat 2024 versions 24.001.30356 and earlier are affected, and Adobe recommends updating through Help > Check for Updates or the official installer.
Magento checkout skimmer campaign targeting nearly 100 stores
Campaign
H score31
First: 09.04.2026 01:34
Last: 09.04.2026 01:34
Sources 1
About this happening:
A Magento checkout skimmer campaign is compromising nearly 100 online stores and stealing payment data at the point of sale, putting shoppers’ card details at immediate ri...
Magento checkout skimmer campaign targeting nearly 100 stores
CampaignAbout this happening: A Magento checkout skimmer campaign is compromising nearly 100 online stores and stealing payment data at the point of sale, putting shoppers’ card details at immediate ri...
Timeline
-
05.09.2026 23:14 2 articles · 1h ago
Magento Open Source and Adobe Commerce StyleSmuggler zero-day actively exploited security flaw
Initial DisclosureExploitation began on September 4, before Adobe had issued any advisory, CVE, patch, or workaround. The flaw allows unauthenticated code execution on Magento Open Source and Adobe Commerce store servers.
Show sources
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores — thehackernews.com — 05.09.2026 23:14
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores — thehackernews.com — 05.09.2026 23:14