Threat Analysis: StyleSmuggler RCE in Magento, BigBear Phishing Risks

Threats & Attacks

Threat Analysis: StyleSmuggler RCE in Magento, BigBear Phishing Risks

This is your Daily Threat Analysis for 8th September 2026. Let’s get right into the real stories you won’t hear in the press releases.

StyleSmuggler Zero-Day in Magento

A critical zero-day vulnerability dubbed StyleSmuggler (CVE-2025-54236) has been actively exploited against Magento and Adobe Commerce since early September. It allows unauthenticated remote code execution, making any unpatched installations open to backdoor attacks. While Adobe has rushed out an emergency patch, many small to medium businesses may not yet be aware or able to apply it quickly. The fact we are reporting this as a critical issue today highlights ongoing complacency in patch management. More details can be found in Adobe’s announcement.

If you run an eCommerce platform, ensure all installations are updated immediately. Exploitation of this magnitude is not a new story; it was a matter of when, not if. The advisory does not mention how frequently these vulnerabilities rise from misconfigured environments or outdated systems.

BigBear Phishing Campaign Targets Microsoft 365

The BigBear 2.0 phishing campaign has managed to steal over 5,000 Microsoft 365 credentials globally, impacting 461 organizations, as detailed by The Register. This operation highlights the critical need for robust phishing awareness and MFA implementation within your business.

This phishing-as-a-service setup is not novel, but the scale and specific targeting underscore the lack of preparedness from affected organizations. Be vigilant - if your IT provider tells you this doesn’t affect you, ask them how many of the impacted businesses thought the same.

Implications for UK SMBs

For UK small businesses, both of these threats underline the importance of rapid patch management and robust phishing defenses. Learning from organizations already affected can prevent similar incidents from occurring in your business. If you’re overwhelmed, adopt a prioritisation process to address vulnerabilities based on severity and exploitability.

Before the next item: if Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically, and pass it to someone who needs the heads-up.

Sources

Filed under

  • smb-security
  • credential-theft
  • remote-access
  • vendor-risk
  • incident-response