Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

https://www.securityweek.com/wp-content/uploads/2025/11/NPM-code-software-development.jpeg

Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports.

Dubbed StyleSmuggler, the security defect enables attackers to inject PHP code into Magento’s template system and evade detection by using the ‘styles’ properties.

According to Sansec, the attack works in two stages: first, the PHP code is injected by generating a failure report, and then Magento executes the code via a failed payment email.

The remote code execution (RCE) flaw works on Magento versions 2.4.7, 2.4.8 and 2.4.9, and has been exploited against deployments running the July and August 2026 patches, Sansec says.

Successful attacks have been deploying a backdoor against Commerce and Magento stores. Written in Rust, the backdoor was seen connecting to a command-and-control (C&C) server and waiting for commands.

Sansec says the exploitation started on September 4, with the backdoor disguised as ‘[kworker/u:8:0]’. On...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more