TTO-2026-0907-104 · September 7, 2026 Active ExploitationZero-Day

StyleSmuggler Zero-Day in Magento and Adobe Commerce Exploited Before Patch Exists

adobe.comStyleSmugglerUnauthenticated RCENo patch available160,000+ sites affectedSansec disclosed Sep 5

Summary

An unpatched zero-day vulnerability dubbed StyleSmuggler, affecting all current versions of Magento Open Source and Adobe Commerce, is being actively exploited to install a persistent Linux backdoor on e-commerce servers. The flaw allows unauthenticated remote code execution through PHP code injection in Magento's template system. Sansec, a Dutch e-commerce security company, confirmed the first victim on September 4 — a store running the latest available security patches. Adobe acknowledged the issue on September 7 and said it was working on a fix but provided no release timeline. No CVE identifier or vendor patch was available at the time of this bulletin.

Timeline

DateEvent
Sep 4, 2026First confirmed exploitation recorded — victim running fully patched Magento 2.4.6-p15
Sep 5, 2026Sansec publishes StyleSmuggler advisory, disclosing early due to active in-the-wild attacks
Sep 7, 2026Adobe Enterprise Support confirms it is working on a fix; no patch or CVE yet assigned
Sep 8, 2026Adobe's next scheduled security release date — patch status at time of publication: unknown

What Happened

StyleSmuggler exploits Magento's template rendering system through PHP code injection, triggering a fabricated failed-payment notification email that causes the server to execute attacker-controlled code. Sansec confirmed the full unauthenticated exploit chain on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9 installations. Stores running the latest available patches are vulnerable.

Successful exploitation installs a small Rust-based backdoor, disguised as a Linux kernel process — appearing as [kworker/u:8:0] on older systems, or as fc-cache copying itself to ~/.cache/fontconfig/ on newer variants. The backdoor adds a cron job repeating every 30 minutes for persistence and communicates with remote command-and-control infrastructure using traffic disguised as NTP — UDP packets to port 123 using hostnames resembling time-syncing infrastructure — to evade firewall inspection. Magento is deployed on over 160,000 websites including 14,000 of the top one million domains. Sansec recommends disabling GraphQL as an interim mitigation and monitoring for unexpected kworker or fc-cache processes and suspicious cron entries. Unexplained "Payment Transaction Failed Reminder" emails may also indicate exploitation.

Domain Intelligence

adobe.com — 62.06

Score sits in the low-trust range. Adobe is the vendor responsible for patching StyleSmuggler as the owner of the Adobe Commerce platform and the Magento Open Source project. The score reflects adobe.com's broader domain trust posture, not the severity of the unpatched vulnerability, which as of this writing has no available fix.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026