securityaffairs.com 7 Sept 2026, 17:49 UTC

Magento Zero Day Enables Unauthenticated Code Execution in Stores

Magento Zero Day Enables Unauthenticated Code Execution in Stores
CyberSIXT Evidence Panel Source marked as original reporting

A newly identified Magento and Adobe Commerce zero-day, nicknamed StyleSmuggler, is under active exploitation and allows unauthenticated attackers to execute code on vulnerable stores. Sansec researchers found that the flaw affects current Magento Open Source releases, including 2.4.7, 2.4.8 and 2.4.9, with exploitation beginning on 4 September.

The attack chain travels through Magento’s template system by injecting malicious PHP code via the GraphQL handling and the styles property, enabling remote code execution during normal workflow such as rendering a “Payment Transaction Failed Reminder” email. Importantly, an updated store can still be exposed even if it has been fully patched through July and August 2026 updates, indicating the issue is not limited to unpatched systems.

Sansec documented two stages of activity and a live backdoor after a successful exploit. The first stage poisons a record and the second forces Magento to run the malicious code during email rendering. A lightweight Rust backdoor then connects to attacker-controlled infrastructure and remains ready for commands.

The implant masquerades as several Linux processes (kworker/u:8:0, fc-cache, chronyd) and communicates with C2 via time-synchronisation traffic—sending 48-byte UDP packets to port 123 to domains resembling time servers, notably ntp.timesync[.]to, sometimes appearing as legitimate system processes to blend in. A separate PHP dropper was observed placing a web shell in the product-image cache, accessible only when a specific X-Cache-Token header is provided.

Adobe planned a security release around 8 September, but no fix date was confirmed. Defenders are advised to consider temporarily disabling GraphQL if mitigations exist, and to hunt for the anomalous processes, unusual outbound UDP traffic, and cron-based persistence indicators, while treating any signs as indicators of compromise and isolating affected hosts.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline