StyleSmuggler Vulnerability – Magento & Adobe Commerce

Incident Report for Liquid Web - Services

Update

As part of our ongoing mitigation efforts, we have implemented additional security protections across affected Magento/Adobe Commerce environments. This includes a full block on GraphQL requests to help reduce the risk of unauthorized code execution.

Customers using headless/PWA storefronts or applications that rely heavily on GraphQL may experience some impact from these protections.

At this time, there is no official vendor patch available.

We recommend continuing to monitor your site for unusual activity or unexpected changes and contacting Support if you notice any issues with your storefront or suspect your site may have been compromised. We will provide further updates once an official security patch becomes available.

Our teams are continuing to monitor the affected environments and the effectiveness of these mitigations. We will continue to assess the situation and provide additional updates as new information becomes available.
Posted Sep 05, 2026 - 19:03 EDT

Identified

We are aware of recent reports regarding a critical, unpatched zero-day vulnerability, commonly referred to as “StyleSmuggler”, affecting Magento and Adobe Commerce.

At this time, our teams are actively reviewing server environments to assess any potential impact. As a precautionary measure, our Security team is implementing the appropriate mitigations while we continue our investigation and monitor for further guidance.
We will provide further updates as more information becomes available.

If you need assistance or have any concerns, please contact our Support team .
Posted Sep 05, 2026 - 09:48 EDT
This incident affects: CPanel, InterWorx, and Plesk.