Feed›Vulnerability›Magento StyleSmuggler zero-day exploited to deploy Linux bac...
VulnerabilityBleeping Computer
9.0 — CRITICAL

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

📅 7 September 2026 at 16:50 UTC📰 Bleeping ComputerView original source ↗
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A zero-day vulnerability in Magento and Adobe Commerce is being exploited to deploy a Linux backdoor, compromising e-commerce websites with over 160,000 installations.

⚙️Technical Details
Affected Systems
MagentoAdobe Commerce
Attack Vectors
PHP code injection through template systemAbuse of 'failed-payment' email to trigger code execution
💥Impact Assessment
Severity: critical
Who Is at Risk
E-commerce websites with Magento and Adobe Commerce installations
🛡️Recommended Actions
1Disable GraphQL as a mitigation measure
2Rotate Magento credentials if suspicion of compromise
3Monitor for 'kworker' or 'fc-cache' processes, suspicious cron entries, and temporary files
📦Affected Products
MagentoAdobe Commerce

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed