The first confirmed StyleSmuggler victim was fully patched. There is still no patch
2026-09-08Security
Sansec says attackers have been exploiting an unpatched Magento and Adobe Commerce flaw since 4 September. The first confirmed victim was running 2.4.6-p15 with the August 2026 patches applied. The trigger is Magento rendering a Payment Transaction Failed Reminder — nobody has to open the email.