Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zero-Day Vulnerability Hits Adobe Commerce Platforms

Zero-Day Vulnerability Hits Adobe Commerce Platforms

Posted on September 7, 2026 By CWS

Cybersecurity experts at Sansec have identified a zero-day vulnerability in Adobe Commerce and Magento platforms, exploited to compromise online retail environments. This breach, known as StyleSmuggler, allows threat actors to insert PHP code into Magento’s template system, bypassing security measures by manipulating ‘styles’ properties.

Uncovering the Attack Mechanism

The StyleSmuggler vulnerability functions in a two-step process. Initially, attackers inject PHP code by creating a failure report, which is then activated through a failed payment email in Magento. This remote code execution (RCE) flaw impacts Magento versions 2.4.7, 2.4.8, and 2.4.9, specifically targeting systems updated with the July and August 2026 patches.

Sansec reports that these breaches have introduced a backdoor into Commerce and Magento stores. This backdoor, coded in Rust, connects to a command-and-control (C&C) server, awaiting directives from the attackers.

Backdoor Disguises and Communication

The exploitation began on September 4, with the initial backdoor masked as ‘[kworker/u:8:0]’. By September 6, a revised version emerged, posing as ‘fc-cache’. The malware cleverly disguises its C&C communications as responses from NTP servers, carrying vital information such as agent ID, hostname, and system details, before relaying the store’s public IP to the C&C server.

Sansec highlights that the StyleSmuggler breach triggers Magento’s standard ‘Payment Transaction Failed Reminder’ email, which can lead to an unexpected surge in these notifications. While legitimate declined payments may cause similar alerts, sudden increases warrant investigation.

Response and Future Outlook

Sansec detected the campaign on September 4th and successfully replicated the attack on clean installations soon after. Adobe plans to release scheduled security updates on September 8, as part of its monthly Patch Tuesday cycle. However, it remains unclear when a specific fix for StyleSmuggler will be deployed.

As the cybersecurity community awaits Adobe’s official response, vigilance and proactive monitoring of e-commerce platforms are essential to mitigate the risks posed by such vulnerabilities.

Security Week News Tags:Adobe Commerce, Backdoor, command-and-control, cyber threats, Cybersecurity, e-commerce security, Magento, Malware, PHP code injection, RCE flaw, Sansec, security patch, StyleSmuggler, zero-day

Post navigation

Previous Post: Telerik UI Vulnerability: Security Flaw Exposes Systems
Next Post: Mathspace Data Breach Exposes Over 1 Million Users

Related Posts

Cisco Addresses Critical Security Vulnerabilities Cisco Addresses Critical Security Vulnerabilities Security Week News
UK Unveils Cybersecurity Strategy with AI Defense Initiative UK Unveils Cybersecurity Strategy with AI Defense Initiative Security Week News
France Probes ‘Foreign Interference’ After Remote Control Malware Found on Passenger Ferry France Probes ‘Foreign Interference’ After Remote Control Malware Found on Passenger Ferry Security Week News
Cisco Resolves Critical SD-WAN Vulnerability Exploited by Hackers Cisco Resolves Critical SD-WAN Vulnerability Exploited by Hackers Security Week News
GitGuardian Secures M to Enhance AI Identity Security GitGuardian Secures $50M to Enhance AI Identity Security Security Week News
Copperhelm Secures M for Innovative Cloud Security Copperhelm Secures $7M for Innovative Cloud Security Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Switzerland to Test Open-Source Alternative to Microsoft 365
  • ScreenConnect Exploited in Cyberattack Campaign
  • Executives Targeted in Microsoft 365 Data Extortion Scam
  • Mathspace Data Breach Exposes Over 1 Million Users
  • Zero-Day Vulnerability Hits Adobe Commerce Platforms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Switzerland to Test Open-Source Alternative to Microsoft 365
  • ScreenConnect Exploited in Cyberattack Campaign
  • Executives Targeted in Microsoft 365 Data Extortion Scam
  • Mathspace Data Breach Exposes Over 1 Million Users
  • Zero-Day Vulnerability Hits Adobe Commerce Platforms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark