[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fV09XQ1rtF-NJ2VWOhebmcK2JPuRXWE8yoOmeJD8gBFk":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"30e630bb-2240-4af2-b679-bbe5189e475d","Magento StyleSmuggler zero-day exploited to deploy Linux backdoor","magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor-9dd82c","A zero-day vulnerability dubbed \"StyleSmuggler\" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]","A zero-day vulnerability, dubbed StyleSmuggler, affecting all Magento and Adobe Commerce versions is being actively exploited to deploy a Rust-based Linux backdoor. Attackers use PHP code injection via the template system to execute arbitrary code, install the backdoor disguised as system processes, and establish persistence via cron jobs. The malware communicates with C2 servers using disguised TLS\u002FWebSockets or NTP traffic and attempts to evade detection by checking for tracing activity.","Magento StyleSmuggler zero-day exploited to deploy Linux backdoor.","Magento StyleSmuggler zero-day exploited to deploy Linux backdoor By Bill Toulas September 7, 2026 12:50 PM 0 A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. The first exploitation incident was recorded on September 4 on a target running the latest security updates. E-commerce security company Sansec says that Adobe Enterprise Support confirmed earlier today that it was working on a fix but did not provide a timeline for its release. Magento is a popular open-source e-commerce platform by Adobe installed on more than 160,000 websites, including 14,000 of the top 1 million sites. Linux backdoor The exploit Sansec observed in the wild abuses Magento’s template system through PHP code injection to generate a fake “failed-payment” email, which triggers code execution. Successful exploitation installs a small Rust-based backdoor as a background process, disguised as [kworker\u002Fu:8:0]. Newer versions disguise the process as fc-cache and copy it to ~\u002F.cache\u002Ffontconfig\u002Ffc-cache. According to Sansec researchers, the attacker also adds a cron job configured to repeat every 30 minutes for persistence. Although Sansec did not observe any follow-on activity, the malware can communicate with remote infrastructure and receive commands. The researchers note that earlier samples of the backdoor used TLS\u002FWebSockets to communicate with the command-and-control (C2) address, while newer versions disguise their traffic as Network Time Protocol (NTP). They send UDP packets to port 123 and use hostnames that resemble time-syncing infrastructure, helping to mask malicious traffic as NTP and get through firewalls. The malware also determines the server's public IP using services including ipify, icanhazip, ident.me, and ipinfo.io, and checks Linux's TracerPid value to detect tracing. If tracing is active, the malware still installs, but does not beacon. Sansec says an unexpected surge of Magento \"Payment Transaction Failed Reminder\" emails may indicate exploitation, and also recommends monitoring for ‘kworker’ or ‘fc-cache’ processes, suspicious cron entries, and temporary files. If there is suspicion of compromise, it is recommended to rotate Magento credentials. At the time of writing, Adobe has not released fixes for StyleSmuggler, but the firm’s next scheduled security release is tomorrow, September 8. Until fixes are made available, Sansec recommends that website administrators disable GraphQL as a mitigation measure. BleepingComputer has contacted Adobe to ask if a fix for StyleSmuggler is planned for rollout tomorrow, but the company has not yet responded. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Hackers exploit critical Adobe Commerce flaw to hijack customer accountsPaperCut releases second emergency patch for exploited flawsPaperCut warns of NG, MF flaw exploited in zero-day attacksArista patches VeloCloud Orchestrator zero-day exploited in attacksCheck Point warns of SmartConsole zero-day exploited in attacks","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmagento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F07\u002F01\u002FAdobe.jpg","2026-09-07T16:50:29+00:00","2026-09-07T18:00:13.674004+00:00",9,[18,21,23,26],{"name":19,"type":20},"Magento","product",{"name":22,"type":20},"Adobe Commerce",{"name":24,"type":25},"Adobe","vendor",{"name":27,"type":28},"Rust","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":29,"icon":31,"name":32,"slug":33},null,"Vulnerabilities","vulnerabilities",[35,40,45,47],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":41},{"id":42,"icon":31,"name":43,"slug":44},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":46},{"id":29,"icon":31,"name":32,"slug":33},{"category":48},{"id":49,"icon":31,"name":50,"slug":51},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[53,56,60,63,66,69,72],{"type":51,"value":54,"context":55},"StyleSmuggler","Name of the zero-day vulnerability and the deployed backdoor",{"type":57,"value":58,"context":59},"mitre_attack","T1059.007","PHP code injection via template system",{"type":57,"value":61,"context":62},"T1037","Cron job for persistence",{"type":57,"value":64,"context":65},"T1071.004","Disguised traffic as NTP for C2 communication",{"type":57,"value":67,"context":68},"T1573.002","TLS\u002FWebSockets for C2 communication",{"type":57,"value":70,"context":71},"T1027","Obfuscated files or information (disguised process name)",{"type":57,"value":73,"context":74},"T1041","Exfiltration Over C2 Channel"]