Adobe Commerce Zero-Day exploited for backdoor online shops

Adobe Commerce Zero-Day exploited for backdoor online shops

As cybersecurity firm Sansec reports, threat actors are exploiting a zero-day vulnerability in the e-commerce platforms Adobe Commerce and Magento to open online stores through backdoors.

Synchronized StyleSmugglerThe vulnerability allows attackers to inject PHP code into Magento’s templating system and use the “Styles” properties to evade detection.

According to Sansec, the attack works in two phases: first, the PHP code is injected by generating an error report, and then Magento executes the code via a failed payment email.

The Remote Code Execution (RCE) flaw works on Magento versions 2.4.7, 2.4.8 and 2.4.9 and was exploited for deployments running the July and August 2026 patches, according to Sansec.

In successful attacks, a backdoor was used against Commerce and Magento shops. Written in Rust, the backdoor connected to a command and control (C&C) server and waited for commands.

According to Sansec, the exploitation began on September 4th, with the backdoor disguised as “(kworker/u:8:0)”. On September 6th, a second version of the backdoor appeared, masquerading as “fc-cache”.

Advertising. Scroll to continue reading.

The malware hides its C&C communication while the NTP server responds. Its messages contain host information including agent ID, hostname and username, memory and disk usage, operating system version, uptime, root access and implant version. In addition, the shop’s public IP address is identified before it is forwarded to C&C.

“StyleSmuggler intentionally triggers Magento’s default “Payment Transaction Failed Reminder” email. Unexpected volumes of these messages are cause for investigation, although legitimately declined payments may generate the same notification,” notes Sansec.

The cybersecurity company explains that the malicious code executes when Magento resends the email, as well as when the email delivery fails, and that no user interaction is required for successful exploitation.

“Sansec discovered the campaign at 22:40 UTC on September 4th and reproduced the chain on clean installations within a few hours,” notes Sansec.

Adobe is expected to roll out planned fixes on September 8th as part of its monthly Patch Tuesday updates, but it’s unclear when StyleSmuggler will be fixed. Safety Week has emailed Adobe for comment and will update this article if the company responds.

Related: HPE addresses critical RCE vulnerabilities in AOS-CX

Related: Cisco warns of unpatched email vulnerabilities and fixes critical switch vulnerabilities

Related: Sangoma Switchvox vulnerabilities are being exploited in the wild

Related: 12-year-old PostgreSQL vulnerability allows database and server takeover

Leave a Reply

Your email address will not be published. Required fields are marked *