VulnerabilityBleeping Computer
9.0 — CRITICAL
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A zero-day vulnerability in Magento and Adobe Commerce is being exploited to deploy a Linux backdoor, compromising e-commerce websites with over 160,000 installations.
⚙️Technical Details
Affected Systems
MagentoAdobe Commerce
Attack Vectors
PHP code injection through template systemAbuse of 'failed-payment' email to trigger code execution
💥Impact Assessment
Severity: critical
Who Is at Risk
E-commerce websites with Magento and Adobe Commerce installations
🛡️Recommended Actions
1Disable GraphQL as a mitigation measure
2Rotate Magento credentials if suspicion of compromise
3Monitor for 'kworker' or 'fc-cache' processes, suspicious cron entries, and temporary files
📦Affected Products
MagentoAdobe Commerce
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
