A Zero-Day Vulnerability in Adobe Commerce and Magento Has Brought Backdoors to Online Stores
Threat actors have been exploiting a zero-day vulnerability in the popular Adobe Commerce and Magento e-commerce platforms to secretly install backdoors on online stores. The malicious activity, dubbed “StyleSmuggler,” allows attackers to inject PHP code into Magento’s template system, making it difficult for store administrators to detect.
The attack works in two stages: first, the PHP code is injected by generating a failure report, and then Magento executes the code via a failed payment email. This exploit is particularly concerning because no user interaction is required for successful exploitation – attackers can execute the malicious code simply by sending a failed payment notification to customers. The vulnerability affects Magento versions 2.4.7, 2.4.8, and 2.4.9, including deployments that applied patches released in July and August of this year.
Once a store has been compromised, the attackers deploy a backdoor written in Rust, which connects to a command-and-control (C&C) server and waits for commands. The malware cleverly disguises its C&C communication as NTP server replies, making it even harder to detect. When communicating with the C&C server, the malware shares information about the store’s configuration, including host details, memory and disk usage, OS version, uptime, root access, and implant version.
Sansec, the cybersecurity firm that discovered the vulnerability, warns that legitimate declined payments can generate similar notification emails, making it essential to investigate unexpected bursts of these messages. The company also notes that the malicious code is executed when Magento resends the email or when email delivery fails – a situation that may occur naturally during normal business operations.
Adobe has announced that it will release scheduled fixes on September 8 as part of its monthly Patch Tuesday updates, but it remains unclear when StyleSmuggler will be addressed specifically. Until then, online store administrators should remain vigilant and monitor their systems closely for any signs of suspicious activity.
If you’re an online store administrator, this is a crucial reminder to stay up-to-date with the latest security patches and regularly review your system logs for any unusual behavior. With the threat landscape constantly evolving, it’s essential to prioritize cybersecurity and invest in robust monitoring and incident response tools to ensure your store remains secure.
Source: SecurityWeek — 2026-09-07