www.securityweek.com 7 Sept 2026, 11:58 UTC

Magento Zero-Day Lets Attackers Backdoor Online Stores via PHP Injection

Magento Zero-Day Lets Attackers Backdoor Online Stores via PHP Injection

SECURITY researchers have linked a zero-day in Adobe Commerce and Magento to a campaign dubbed StyleSmuggler, which is being used to backdoor online stores. The flaw allows remote code execution by injecting PHP into Magento’s template system and evading detection through the use of the platform’s “styles” properties.

Sansec describes a two-stage attack: first, attackers inject code by triggering a failure report, then Magento executes the code via a failed payment email, enabling backdoor installation without user interaction.

Evidence from Sansec indicates the flaw affects Magento deployments on versions 2.4.7, 2.4.8 and 2.4.9, and the activity coincided with patches released in July and August 2026.

The backdoor itself is written in Rust and communicates with a command-and-control server, with later variants disguising itself as “kworker/u:8:0” and then as “fc-cache.” The malware hides its C2 traffic behind NTP server replies and exfiltrates system details such as agent ID, hostname, memory and disk usage, OS version, uptime, root access, and the implant version, including the store’s public IP prior to beaconing.

Sansec notes that the attack chain began on 4 September 22:40 UTC and was replicable on clean installations within hours. Adobe has not yet confirmed a remediation timeline beyond stating that fixes were expected with September’s Patch Tuesday updates.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline