• News/
  • bleepingcomputer-20260907165029

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

BleepingComputer
·
Bill Toulas
·
Published Sep 7, 2026
·
Updated

A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. The first exploitation incident was recorded on September 4 on a target running the latest security updates. E-commerce security company Sansec says that Adobe Enterprise Support confirmed earlier today that it was working on a fix but did not provide a timeline for its release. Magento is a popular open-source e-commerce platform by Adobe installed on more than 160,000 websites, including 14,000 of the top 1 million sites. The exploit Sansec observed in the wild abuses Magento’s template system through PHP code injection to generate a fake “failed-payment” email, which triggers code execution. Successful exploitation installs a small Rust-based backdoor as a background process, disguised as [kworker/u:8:0]. Newer versions disguise the process as fc-cache and copy it to ~/.cache/fontconfig/fc-cache. According to Sansec researchers, the attacker also adds a cron job configured to repeat every 30 minutes for persistence. Although Sansec did not observe any follow-on activity, the malware can communicate with remote infrastructure and receive commands. The researchers note that earlier samples of the backdoor used TLS/WebSockets to communicate with the command-and-control (C2) address, while newer versions disguise their traffic as Network Time Protocol (NTP). They send UDP packets to port 123 and use hostnames that resemble ti...

Read full article

Affected Software

2 affected components
Adobe Magento=all versions
Adobe Adobe Commerce=all versions

Frequently Asked Questions

1

Which Magento and Adobe Commerce deployments are affected?

The zero-day affects all versions of Magento and Adobe Commerce. The first observed incident targeted a deployment running the latest security updates.

2

How does the observed exploit execute code?

Sansec observed attackers abusing Magento’s template system through PHP code injection. The exploit generates a fake “failed-payment” email that triggers code execution.

3

What persistence and evasion techniques does the installed backdoor use?

The Rust-based backdoor runs in the background disguised as [kworker/u:8:0], while newer versions use the name fc-cache and copy themselves to ~/.cache/fontconfig/fc-cache. Attackers also add a cron job that runs every 30 minutes for persistence.

4

Is a vendor fix available?

Adobe Enterprise Support confirmed that it was working on a fix, but did not provide a release timeline.

5

What post-compromise activity has been confirmed?

Sansec did not observe follow-on activity after installation. However, the malware can communicate with remote infrastructure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203