A new critical security vulnerability affecting Magento Open Source and Adobe Commerce is currently being actively exploited.
The vulnerability, named StyleSmuggler, was publicly disclosed by security researchers at Sansec on September 5, 2026. Confirmed attacks began on September 4.
Because the vulnerability affects currently supported Magento installations and an observed exploitation path involves Magento's GraphQL endpoint, we have decided to temporarily pause Classbell's Magento GraphQL integrations and deployments as a precaution.
What is StyleSmuggler?
StyleSmuggler is an unpatched Magento and Adobe Commerce zero-day vulnerability capable of leading to unauthenticated Remote Code Execution (RCE).
According to Sansec's investigation, the complete attack chain has been reproduced against clean installations of:
- Magento Open Source 2.4.7
- Magento Open Source 2.4.8
- Magento Open Source 2.4.9
A compromised Magento 2.4.6-p15 installation was also identified despite having the July and August 2026 security patches installed.
This makes the issue particularly important because simply running a recently patched Magento installation may not currently provide protection against StyleSmuggler.
Is this a Magento GraphQL vulnerability?
Not exactly.
GraphQL is involved in an observed exploitation path, but describing StyleSmuggler simply as a “GraphQL vulnerability” would be misleading.
The attack abuses Magento's template processing and styles properties to introduce malicious code that can later be executed by Magento. Security researchers have observed malicious requests targeting the /graphql endpoint as part of the exploitation chain.
Until an official fix becomes available, temporarily disabling Magento GraphQL has been suggested as one possible defensive measure for affected environments without other verified protection.
Why Classbell is taking action
Classbell uses Magento APIs, including GraphQL, to communicate with Magento stores and provide AI-powered e-commerce functionality.
There is currently no indication that Classbell itself has been compromised or that the vulnerability originates from Classbell.
Nevertheless, our approach is simple:
When an actively exploited zero-day affects an integration layer we depend on, security takes priority over availability.
We are therefore temporarily pausing Magento GraphQL integrations and new deployments while we evaluate the vulnerability and the available mitigations.
This is a precautionary measure intended to reduce unnecessary exposure while the Magento security community and Adobe investigate the issue.
What should Magento merchants do?
Magento and Adobe Commerce merchants should treat StyleSmuggler as a high-priority security issue.
Store owners should review the latest security guidance, investigate their environments for indicators of compromise, consider temporarily restricting GraphQL where technically possible, and apply an official Adobe security fix as soon as one becomes available.
Simply installing previous Magento security patches should not be considered sufficient protection against this newly disclosed zero-day.
When will Classbell restore normal operation?
We are actively monitoring updates from Adobe, Magento security researchers and the wider Magento ecosystem.
Classbell's normal Magento GraphQL integrations will resume once an official Adobe fix or a sufficiently verified mitigation is available and we are satisfied that restoring the integration does not introduce unnecessary security risk.
We will publish another update when the situation changes.
Last updated: September 7, 2026
Stay safe and keep your Magento installations monitored and up to date.
— Classbell Team