Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Sansec found attackers exploiting an Adobe Commerce/Magento zero-day (StyleSmuggler) since September 4 to deploy Rust backdoors on online stores.
Threat actors are actively exploiting a zero-day RCE in Adobe Commerce and Magento 2.4.7-2.4.9, injecting PHP code via generated failure reports and executing it through Magento's payment-failure email, with no user interaction required. Exploitation began September 4 and succeeds even against stores running the July and August 2026 patches; the Rust backdoor disguises itself as kworker/u:8:0 or fc-cache and hides C&C communication inside fake NTP replies. Adobe's September 8 Patch Tuesday updates may not include a StyleSmuggler fix.
- StyleSmuggler exploits template 'styles' properties to inject PHP and evade detection
- Backdoor written in Rust, beacons via NTP-disguised traffic with host details
- Exploitation started September 4; second backdoor variant emerged September 6
- Affects Magento 2.4.7, 2.4.8, 2.4.9 including latest patches
- Sudden bursts of 'Payment Transaction Failed Reminder' emails indicate possible compromise
Full article376 words · extracted from securityweek.com · click to collapse
Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports.
Dubbed StyleSmuggler, the security defect enables attackers to inject PHP code into Magento’s template system and evade detection by using the ‘styles’ properties.
According to Sansec, the attack works in two stages: first, the PHP code is injected by generating a failure report, and then Magento executes the code via a failed payment email.
The remote code execution (RCE) flaw works on Magento versions 2.4.7, 2.4.8 and 2.4.9, and has been exploited against deployments running the July and August 2026 patches, Sansec says.
Successful attacks have been deploying a backdoor against Commerce and Magento stores. Written in Rust, the backdoor was seen connecting to a command-and-control (C&C) server and waiting for commands.
Sansec says the exploitation started on September 4, with the backdoor disguised as ‘[kworker/u:8:0]’. On September 6, a second version of the backdoor emerged, disguising itself as ‘fc-cache’.
Advertisement. Scroll to continue reading.
The malware hides its C&C communication as NTP server replies. Its messages carry host information, including agent ID, hostname and username, memory and disk usage, OS version, uptime, root access, and implant version. It also identifies the store’s public IP before beaconing to the C&C.
“StyleSmuggler deliberately triggers Magento’s standard ‘Payment Transaction Failed Reminder’ email. Unexpected bursts of these messages are a reason to investigate, although legitimate declined payments can generate the same notification,” Sansec notes.
The cybersecurity firm explains that the malicious code is executed when Magento resends the email, as well as when email delivery fails, and that no user interaction is required for successful exploitation.
“Sansec found the campaign on September 4th, 22:40 UTC and reproduced the chain on clean installations within hours,” Sansec notes.
Adobe is expected to roll out scheduled fixes on September 8, as part of its monthly Patch Tuesday updates, but it is unclear when StyleSmuggler will be addressed. SecurityWeek has emailed Adobe for a statement and will update this article if the company responds.
Related: HPE Patches Critical RCE Vulnerabilities in AOS-CX
Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
Related: Sangoma Switchvox Vulnerabilities Exploited in the Wild
Related: 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/adobe-commerce-zero-day-exploited-to-backdoor-online-stores/