An unpatched flaw named StyleSmuggler is letting attackers backdoor Magento and Adobe Commerce stores with no login.