Ethical Hacking News
A recent vulnerability in Magento and Adobe Commerce has been exploited by attackers, resulting in the backdoor installation on online stores. The vulnerability, known as StyleSmuggler, was discovered by Dutch e-commerce security company Sansec and was first reported on September 5, 2026. Learn more about the vulnerability and how it can be exploited.
A recent vulnerability in Magento and Adobe Commerce has been exploited by attackers, resulting in the backdoor installation on online stores. The vulnerability, known as StyleSmuggler, was discovered by Dutch e-commerce security company Sansec and was first reported on September 5, 2026. The affected versions are 2.4.9, 2.4.8, and 2.4.7, but Adobe has not confirmed which versions are affected. The attack allows attackers to run malicious code on an online store's server without logging in, giving them complete control over the store's infrastructure. Disrex Group has provided a cleanup guide for stores that have been compromised, including steps such as preserving evidence, removing the cron entry, and rotating Magento credentials. Adeobe has not published an advisory, a CVE identifier, a patch, or a workaround, and its next scheduled security release is on September 8. The vulnerability has been exploited in several stores, with some attackers making outbound connections to the store's own Redis instance.
A recent vulnerability in Magento and Adobe Commerce has been exploited by attackers, resulting in the backdoor installation on online stores. The vulnerability, known as StyleSmuggler, was discovered by Dutch e-commerce security company Sansec and was first reported on September 5, 2026. The exploit allows attackers to run malicious code on an online store's server without logging in, giving them complete control over the store's infrastructure.
According to Sansec, the vulnerability was discovered in Magento and Adobe Commerce versions 2.4.9, 2.4.8, and 2.4.7. The company has not published a reproduction on Adobe Commerce or on Adobe Commerce on Cloud, and Adobe has not confirmed which versions are affected. Sansec has not said how many stores have been compromised, but it has recommended rotating Magento credentials wherever the process has been identified.
The attack works in two stages, according to Sansec's outline. It first plants PHP code in a file that Magento itself writes, for example, when generating a failure report. Then it makes Magento execute that file by triggering the platform's standard "Payment Transaction Failed Reminder" email. The code runs while Magento renders the message, so no one has to open it, and the attack can succeed even if email delivery fails.
Sansec has not yet published the full exploit chain and said a breakdown of the chain, the dropper, and the implant will follow in an update. However, it has provided some indicators for the implant, including a process name of "[kworker/u:8:0]" owned by a non-root user, a file path of "~/.local/share/.gvfsd/gvfsd-user", a cron entry that restarts the implant every five minutes, and a SHA-256 hash of "e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7".
Disrex Group, a Magento hosting and development company, has also analyzed the exploit and has provided its own set of indicators and mitigations. Disrex's main mitigation adds a check to three methods in Magento's dependency-injection code scanners, preventing them from running outside the command line. The company has also published a cleanup guide for stores that have been compromised, which includes steps such as preserving evidence, removing the cron entry, and rotating Magento credentials.
Adobe has not published an advisory, a CVE identifier, a patch, or a workaround, and its Adobe Commerce security bulletin index lists nothing after the August 11 update. However, the company's next scheduled security release is on September 8, Sansec said, and it is not yet known whether that release will cover this bug.
The vulnerability has been exploited in several stores, including one store that carried the same line 1,728 times, and the implant re-added it within a second of removal. On one of the two stores, the implant made no outbound connection at all, but it held 28 connections to the store's own Redis instance on port 6379. It read Magento's session storage from it, Disrex said.
In response to the vulnerability, hosting providers Nexcess and Liquid Web posted identical incident notices on September 5, stating they were reviewing their server environments and implementing precautionary measures. The Hacker News has reached out to Adobe, Sansec, Disrex, and Graycore for comment, and will update the story if we hear back.
Related Information:
https://www.ethicalhackingnews.com/articles/Exploitation-of-Unpatched-Magento-and-Adobe-Commerce-Vulnerabilities-A-Comprehensive-Analysis-of-the-Zero-Day-Threat-ehn.shtml
https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html
Published: Sat Sep 5 16:49:08 2026 by llama3.2 3B Q4_K_M