Cybersecurity

StyleSmuggler Vulnerability in Magento Exploited to Deploy a Backdoor on Linux Servers

A zero-day vulnerability in all versions of Magento and Adobe Commerce is being exploited to plant a backdoor written in Rust, while Adobe has not yet released a fix. Researchers recommend temporarily disabling GraphQL and monitoring specific indicators of compromise until an update becomes available.

2026-09-07
3 min read
11 views
فريق تحرير certi.news
StyleSmuggler Vulnerability in Magento Exploited to Deploy a Backdoor on Linux Servers

All versions of Magento and Adobe Commerce are being targeted in attacks exploiting a zero-day vulnerability dubbed StyleSmuggler, with the goal of installing a backdoor on Linux servers. Sansec, a company specializing in e-commerce platform security, recorded the first exploitation incident on September 4, 2026, against a site running the latest available security updates.

Adobe Enterprise Support confirmed to Sansec that it is working on a fix for the vulnerability, but did not specify when it would be released. As of the time the information was published, Adobe had not released an update addressing StyleSmuggler, while the company’s next regular security release was scheduled for September 8.

How does the exploitation work?

The attack exploits Magento’s template system by injecting PHP instructions, then creates a fake email message with a subject indicating that a payment failed. Processing this message causes the malicious code to run on the server.

After successful exploitation, the attackers install a small Rust-based backdoor and run it as a background process. The program initially masquerades as the kworker/u:8:0 process, while newer versions use the name fc-cache and copy themselves to ~/.cache/fontconfig/fc-cache. The program also adds a cron job that runs every 30 minutes to maintain persistence.

Sansec did not detect subsequent activity from the backdoor in the samples it examined, but explained that it is capable of connecting to external infrastructure and receiving commands. Older samples used TLS and WebSockets to connect to the command server, while newer samples masquerade as NTP time-synchronization protocol traffic by sending UDP packets to port 123 and using domain names resembling time-synchronization infrastructure.

Indicators that may reveal a compromise

Sansec believes that an unusual increase in Magento messages titled Payment Transaction Failed Reminder could indicate exploitation. Other indicators include the appearance of processes named kworker or fc-cache, unusual cron entries, and suspicious temporary files.

The backdoor also checks the server’s public IP address through services such as ipify, icanhazip, ident.me, and ipinfo.io, and examines the Linux TracerPid value to detect tracing processes. If tracing is detected, it continues the installation but does not send signals to the remote infrastructure.

What changes in practice for store administrators?

The incident is significant because of the breadth of the affected platform; the article states that Magento is installed on more than 160,000 sites, including 14,000 among the world’s top one million websites. Because exploitation was observed on an updated system, installing only the latest available updates does not by itself prove protection against this vulnerability before a dedicated fix is released.

Until a patch becomes available, Sansec recommends disabling GraphQL as a mitigation measure, in addition to rotating Magento credentials when a compromise is suspected. The source does not establish whether the September 8 release will include a fix for StyleSmuggler; BleepingComputer requested clarification from Adobe but had not received a response by the time the article was prepared.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news