Ethical Hacking News
Ambush in the Digital Realm: The StyleSmuggler Vulnerability Exposed in Adobe Commerce and Magento
Adobe has issued a critical security patch for its Commerce and Magento Open Source platforms due to a maximum-severity vulnerability known as StyleSmuggler (CVE-2026-75650).The vulnerability arises from a flaw in Magento's template system, allowing PHP code injection to generate a "Payment Transaction Failed Reminder" email, which triggers code execution.The flaw affects various versions of Adobe Commerce and Magento Open Source, including 2.4.9-2026-aug and earlier, as well as some B2B products.Threat actors have exploited the vulnerability since September 4, 2026, deploying a Rust-based Linux backdoor and a PHP web shell to compromise merchants.Adobe advises affected merchants to apply the patch and rotate their encryption keys to mitigate the risk, and to monitor systems for suspicious activity.
Adobe has issued a critical security patch for its Commerce and Magento Open Source platforms, addressing a maximum-severity vulnerability known as StyleSmuggler (CVE-2026-75650). This zero-day exploit has been actively targeted by threat actors, who have leveraged it to deploy a Rust-based Linux backdoor and a PHP web shell, compromising several Adobe Commerce merchants.
The vulnerability, discovered by Sansec, arises from a flaw in Magento's template system, which allows PHP code injection to generate a "Payment Transaction Failed Reminder" email. This, in turn, triggers code execution, providing an entry point for attackers to inject malicious code into the system. The flaw affects various versions of Adobe Commerce and Magento Open Source, including 2.4.9-2026-aug and earlier, as well as some B2B products.
According to Adobe, the vulnerability has been exploited in the wild since September 4, 2026, with threat actors taking advantage of the issue to deploy a Rust-based Linux backdoor. This backdoor connects to an external server and awaits further instructions from the attackers. Furthermore, the vulnerability has also been abused to deliver a PHP dropper on susceptible sites, which writes a web shell capable of executing arbitrary PHP code.
A Dutch e-commerce security company, Disrex, revealed that one of its Magento servers was compromised just 50 minutes after the first confirmed StyleSmuggler exploitation was reported. This highlights the rapid spread of this vulnerability and the importance of swift patching and remediation.
The patch, titled VULN-39341, is available for download from the Magento repository, and Adobe advises that affected merchants apply the patch and rotate their encryption keys to mitigate the risk. Additionally, the company emphasized the importance of monitoring systems for suspicious activity and rotating encryption keys to prevent exploitation.
The StyleSmuggler vulnerability serves as a stark reminder of the ever-present threat landscape in the digital world. As technology advances, new vulnerabilities emerge, and it is crucial for organizations to remain vigilant and proactive in addressing these threats. By staying informed and taking swift action, businesses can reduce the risk of exploitation and protect their systems from potential attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/Ambush-in-the-Digital-Realm-The-StyleSmuggler-Vulnerability-Exposed-in-Adobe-Commerce-and-Magento-ehn.shtml
https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
Published: Tue Sep 8 05:07:41 2026 by llama3.2 3B Q4_K_M