WAF Watch: Magento zero-day, school-year outages, and Drupal XSS
Mac Clark · September 8, 2026
A short roundup of what hit websites this past stretch — and what to do about it if you run campus or agency sites. Fear is cheap; checklists are useful. Here’s what operators should actually touch this week.
ProtectMyWebsite is the WAF that tells you what’s safe to block — rules start in count, then your dashboard shows what to promote. You still decide.
1. StyleSmuggler — Magento / Adobe Commerce 0-day under active attack
Sansec disclosed StyleSmuggler on September 5: unauthenticated RCE against Magento Open Source and Adobe Commerce including 2.4.x (reproduced on clean 2.4.7–2.4.9). Exploitation began September 4, before a CVE or patch. The chain abuses Magento’s template/styles path and GraphQL-shaped requests, then failed-payment email rendering for server-side code. Follow-on implants show up as kworker, fc-cache, or chronyd; PHP webshells land under media caches. Sansec’s research and a Disrex write-up have the technical detail. Campus bookstores, alumni shops, foundation storefronts, and ticket booths are in scope; agencies with Adobe Commerce payment portals are the same.
Do this: Inventory Magento and Adobe Commerce installs (including vendors). Hunt suspicious processes and pub/media/**/*.php per Sansec. Until Adobe ships a fix: emergency mitigations (Sansec notes a temporary GraphQL disable) plus body- and header-aware virtual-patch rules in count. Promote only after the junk hits look clean.
2. France’s school-year start — education platforms forced back to paper
On September 1, the rentrée, cyber disruption hit the Nantes and Toulouse academies — messaging, absence, and grades went offline and schools fell back to paper. Continuity was the emphasis; personal data was not confirmed compromised. Imago’s report is the public write-up. The lesson: portal failure at peak season is the incident.
Do this: Treat admissions, SIS, parent portals, and gradebooks as shared infrastructure. Pre-stage status pages and paper fallbacks. Rate-limit and challenge auth and forms in count first. Rehearse comms ownership for when the LMS is slow.
3. Drupal Monster Menus — stored XSS (CVE-2026-81201)
SA-CONTRIB-2026-116: stored XSS in tree and page titles when HTML is not sanitized. Fixed in monster_menus 9.5.3. It needs a user who can create pages with HTML titles — enough for campus session-theft risk. See the Drupal advisory.
Do this: composer require 'drupal/monster_menus:^9.5.3', update, and clear caches. Audit who can create pages. Put edge XSS signatures in count on admin and tree paths; promote only on probe hits.
4. Feide / Sikt — shared higher-ed login floods
Sikt reported DDoS in early September after late-August Feide and Studentweb hits. On September 4, Feide instability cascaded. Availability attack, no confirmed intrusion. Khrono covered Feide; Dig.watch noted the same pattern on the civic side with Digdir / ID-porten in late August.
Do this: Shared IdP is blast radius. Rate-limit and bot-challenge auth, keep origin IPs private, and have a status plan for when the IdP is the target.
5. Form and upload abuse
WordPress Imagick/Ghostscript RCE and the Elementor Pro upload chain still matter: they ride multipart/POST bodies. StyleSmuggler is the same idea. Forgotten campus forms are how these land.
Do this: Map public forms and uploads. Virtual-patch upload abuse in count. Confirm the body field before you promote.
Tip of the week
Zero-day week is when count mode earns its keep.
Put body- and header-aware virtual-patch rules in count. After about a day, the dashboard shows what those rules actually hit. Then one click to promote. Confirm the match is the exploit (GraphQL, multipart, title fields), not junk.
That’s how we run ProtectMyWebsite: rules start in count; after 24 hours the dashboard shows what’s safe to block — one click. Promote Copilot reads your count window and explains what's safe to promote or should hold — you still click once.
Campus Estate is quote on request — talk to sales team. We do not publish Estate list prices.
If you run campus or agency sites: scan your site, see what WAF count mode is, managed WAF for university and college websites, managed WAF for government and public-sector websites, managed WAF for Magento and Adobe Commerce, managed WAF for Drupal sites, and start a 14-day trial.