Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
A zero-day vulnerability named StyleSmuggler in Adobe Commerce and Magento e-commerce platforms allows attackers to execute remote code and deploy a stealthy backdoor. The flaw affects Magento versions 2.4.7, 2.4.8, and 2.4.9, including installations with July and August 2026 patches. Attackers inject PHP code via Magento's template system using the 'styles' properties and trigger execution through failed payment email notifications without user interaction. The backdoor, written in Rust, disguises itself as system processes and communicates with a command-and-control server using covert channels. Adobe is expected to release a fix on September 8, 2026, but the exact patch addressing this zero-day is not yet confirmed.
AI Analysis
Technical Summary
The StyleSmuggler zero-day vulnerability enables remote code execution on Adobe Commerce and Magento stores by injecting PHP code into the template system, leveraging the 'styles' properties to evade detection. The attack chain involves generating a failure report that injects malicious code, which is then executed when Magento sends or resends a failed payment email. This vulnerability affects Magento versions 2.4.7, 2.4.8, and 2.4.9, including those patched in July and August 2026. Exploitation began on September 4, 2026, with attackers deploying a Rust-based backdoor that disguises itself as legitimate system processes and communicates with a command-and-control server via NTP-like messages. The backdoor collects host information and waits for commands, enabling persistent unauthorized access. Adobe is scheduled to release patches on September 8, 2026, but it is unclear if the zero-day will be addressed then.
Potential Impact
Successful exploitation allows attackers to execute arbitrary PHP code remotely on affected Adobe Commerce and Magento stores, leading to the deployment of a stealthy backdoor. This backdoor provides persistent unauthorized access, enabling attackers to communicate with a command-and-control server, gather system information, and potentially control the compromised store. The vulnerability requires no user interaction and has been actively exploited since early September 2026. The presence of the backdoor poses significant risks to the confidentiality, integrity, and availability of affected e-commerce platforms.
Mitigation Recommendations
Adobe is expected to release official patches on September 8, 2026, as part of its monthly Patch Tuesday updates. Users should apply these updates promptly once available and monitor Adobe's advisories for confirmation that the StyleSmuggler zero-day is addressed. Until the patch is released, administrators should investigate unexpected bursts of 'Payment Transaction Failed Reminder' emails, as these may indicate exploitation attempts. No other specific mitigations are confirmed by the vendor at this time.
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Description
A zero-day vulnerability named StyleSmuggler in Adobe Commerce and Magento e-commerce platforms allows attackers to execute remote code and deploy a stealthy backdoor. The flaw affects Magento versions 2.4.7, 2.4.8, and 2.4.9, including installations with July and August 2026 patches. Attackers inject PHP code via Magento's template system using the 'styles' properties and trigger execution through failed payment email notifications without user interaction. The backdoor, written in Rust, disguises itself as system processes and communicates with a command-and-control server using covert channels. Adobe is expected to release a fix on September 8, 2026, but the exact patch addressing this zero-day is not yet confirmed.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The StyleSmuggler zero-day vulnerability enables remote code execution on Adobe Commerce and Magento stores by injecting PHP code into the template system, leveraging the 'styles' properties to evade detection. The attack chain involves generating a failure report that injects malicious code, which is then executed when Magento sends or resends a failed payment email. This vulnerability affects Magento versions 2.4.7, 2.4.8, and 2.4.9, including those patched in July and August 2026. Exploitation began on September 4, 2026, with attackers deploying a Rust-based backdoor that disguises itself as legitimate system processes and communicates with a command-and-control server via NTP-like messages. The backdoor collects host information and waits for commands, enabling persistent unauthorized access. Adobe is scheduled to release patches on September 8, 2026, but it is unclear if the zero-day will be addressed then.
Potential Impact
Successful exploitation allows attackers to execute arbitrary PHP code remotely on affected Adobe Commerce and Magento stores, leading to the deployment of a stealthy backdoor. This backdoor provides persistent unauthorized access, enabling attackers to communicate with a command-and-control server, gather system information, and potentially control the compromised store. The vulnerability requires no user interaction and has been actively exploited since early September 2026. The presence of the backdoor poses significant risks to the confidentiality, integrity, and availability of affected e-commerce platforms.
Mitigation Recommendations
Adobe is expected to release official patches on September 8, 2026, as part of its monthly Patch Tuesday updates. Users should apply these updates promptly once available and monitor Adobe's advisories for confirmation that the StyleSmuggler zero-day is addressed. Until the patch is released, administrators should investigate unexpected bursts of 'Payment Transaction Failed Reminder' emails, as these may indicate exploitation attempts. No other specific mitigations are confirmed by the vendor at this time.
Technical Details
- Classification
- {"confidence":0.8,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/adobe-commerce-zero-day-exploited-to-backdoor-online-stores/","fetched":true,"fetchedAt":"2026-09-07T12:07:28.018Z","wordCount":1042}
Threat ID: 6a9ea900acd9273b49923bbe
Added to database: 09/07/2026, 12:07:28 UTC
Last enriched: 09/07/2026, 12:07:40 UTC
Last updated: 09/07/2026, 13:08:03 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.