Tendvane

← All articles

SecuritySeptember 7, 2026

There's a hole in a lot of online shops right now, and no patch for it

Magento is the software running the checkout at a great many independent online shops, the ones that are not Amazon and not on Shopify. Roughly 111,500 of them were active earlier this year, by StoreLeads' count. On 5 September the Dutch firm Sansec published details of a flaw in all current versions, including the newest 2.4.9, and explained why it was not waiting for a vendor fix: "Sansec is publishing early because stores are being compromised right now."

The attacks started the previous evening, 4 September at 22:20 UTC. The flaw, named StyleSmuggler, needs no login and no help from anybody. An attacker slips PHP code into the store's template system, then triggers it by making the shop send its "Payment Transaction Failed Reminder" email, at which point the code runs on the server. What lands afterwards is a backdoor that names itself after ordinary Linux processes like chronyd and fc-cache so it does not stand out in a process list. As of 6 September there was no CVE number, no Adobe advisory and no patch. Adobe's next scheduled security release is 8 September.

None of that is something a shopper can act on, and that is the honest problem here. What a break-in like this usually leads to is a card skimmer quietly added to the checkout page, invisible in the page you are looking at. So the defence is in how you pay rather than what you notice. Pay through PayPal, Apple Pay or Google Pay where a small shop offers it, because the shop never sees your card number. Decline the offer to save your card for next time. And read your statement rather than only your balance, because skimmed cards get tested with small amounts first.

Tendvane cannot patch a shop's server and will not claim to. The part it does cover is your side of the transaction: its app-update tool uses winget to show which programs on your PC, browsers included, are running old versions, since an out-of-date browser is what makes a tampered page dangerous rather than merely dishonest.

Sources

Download Tendvane