Cybersecurity experts at Sansec have identified a zero-day vulnerability in Adobe Commerce and Magento platforms, exploited to compromise online retail environments. This breach, known as StyleSmuggler, allows threat actors to insert PHP code into Magento’s template system, bypassing security measures by manipulating ‘styles’ properties.
Uncovering the Attack Mechanism
The StyleSmuggler vulnerability functions in a two-step process. Initially, attackers inject PHP code by creating a failure report, which is then activated through a failed payment email in Magento. This remote code execution (RCE) flaw impacts Magento versions 2.4.7, 2.4.8, and 2.4.9, specifically targeting systems updated with the July and August 2026 patches.
Sansec reports that these breaches have introduced a backdoor into Commerce and Magento stores. This backdoor, coded in Rust, connects to a command-and-control (C&C) server, awaiting directives from the attackers.
Backdoor Disguises and Communication
The exploitation began on September 4, with the initial backdoor masked as ‘[kworker/u:8:0]’. By September 6, a revised version emerged, posing as ‘fc-cache’. The malware cleverly disguises its C&C communications as responses from NTP servers, carrying vital information such as agent ID, hostname, and system details, before relaying the store’s public IP to the C&C server.
Sansec highlights that the StyleSmuggler breach triggers Magento’s standard ‘Payment Transaction Failed Reminder’ email, which can lead to an unexpected surge in these notifications. While legitimate declined payments may cause similar alerts, sudden increases warrant investigation.
Response and Future Outlook
Sansec detected the campaign on September 4th and successfully replicated the attack on clean installations soon after. Adobe plans to release scheduled security updates on September 8, as part of its monthly Patch Tuesday cycle. However, it remains unclear when a specific fix for StyleSmuggler will be deployed.
As the cybersecurity community awaits Adobe’s official response, vigilance and proactive monitoring of e-commerce platforms are essential to mitigate the risks posed by such vulnerabilities.
